CVE-2018-15754

CVE-2018-15754

Cloud Foundry UAA, all versions in v60.x, v61.x, v62.x, v63.x, and v64.x contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.

Source: CVE-2018-15754

답글 남기기

이메일 주소는 공개되지 않습니다. 필수 필드는 *로 표시됩니다