CVE-2018-1195
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/03/2018
Last modified:
29/08/2022
Description
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an access token, either due to lack of client credentials or revocation, would allow authentication.
Impact
Base Score 3.x
8.80
Severity 3.x
HIGH
Base Score 2.0
6.50
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:* | 1.46.0 (excluding) | |
| cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* | 1.3.0 (excluding) | |
| cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | 283 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



