CVE-2018-11082

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
05/10/2018
Last modified:
09/10/2019

Description

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:cloudfoundry_uaa:*:*:*:*:*:*:*:* 4.20.0 (excluding)
cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:*:*:*:*:*:*:*:* 61.0 (excluding)


References to Advisories, Solutions, and Tools