Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Vulnerable Products 2
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Cloudfoundry Cf-Deployment
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
|
> 48.7.0
|
<= 54.11.0
|
|
Cloudfoundry Uaa-Release
cpe:2.3:a:cloudfoundry:uaa-release:*:*:*:*:*:*:*:*
|
77.30.0
|
78.8.0
|