GHSA-47fq-mm42-6v8w
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 3, 2025 6:48 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.