Cloud Foundry denial of service vulnerability
High severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Feb 29, 2024
Package
Affected versions
>= 3.10.0, < 3.12.0
< 3.9.8
Patched versions
3.12.0
3.9.8
Description
Published by the National Vulnerability Database
Mar 10, 2017
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Feb 29, 2024
Last updated
Feb 29, 2024
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
References