GHSA-cgrg-x34r-78f3
GitHub Security Advisory
Cloud Foundry UAA password reset vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions prior to v24.9, 30.x versions prior to 30.2, and other versions prior to v36. Privileged users in one zone are allowed to perform a password reset for users in a different zone.
Affected Packages
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
2.0.0
(fixed in 2.7.4.16)
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
3.0.0
(fixed in 3.6.10)
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
3.7.0
(fixed in 3.9.12)
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
3.10.0
(fixed in 3.17.0)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 31, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.