GHSA-hxgw-7539-pv7r
GitHub Security Advisory
Cloud Foundry denial of service vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
Affected Packages
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
3.10.0
(fixed in 3.12.0)
Maven
org.cloudfoundry.identity:cloudfoundry-identity-server
Affected versions:
0
(fixed in 3.9.8)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 30, 2025 6:32 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.