HIGH🇵🇱 Wersja polska

CVE-2018-11083

CVSS 8.1v3.1pub. 2018-10-05upd. 2024-11-21

Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens when using UAA for authentication. A remote attacker with an admin refresh token given by UAA can be used to access BOSH resources without obtaining an access token, even if their user no longer has access to those resources.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Cloud Foundry Bosh

    APP
    Cloud Foundry
    264.1 – 264.14.0 (excl.)265.1.0 – 265.7.0 (excl.)266.2.0 – 266.8.0 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-11271HIGH7.8same product

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact cre...

CVE-2017-4961HIGH8.8same product

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x v...

CVE-2026-41009MEDIUM4.3same product

Gdy dyrektor wysyła długotrwałe żądanie (np. compile_package), odpowiedź JSON agenta jest konsumowana przez Ag...

CVE-2026-41704MEDIUM6.8same product

AgentClient#handle_method (linie 264-303) przetwarza każdą odpowiedź NATS. Wywołuje inject_compile_log (linia ...

CVE-2018-15800HIGH8.1same vendor

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remo...