Vulnerability Name: | CVE-2015-3189 (CCN-127017) | ||||||||||||
Assigned: | 2015-04-10 | ||||||||||||
Published: | 2015-04-10 | ||||||||||||
Updated: | 2021-08-25 | ||||||||||||
Summary: | With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address to a new one. This vulnerability is applicable only when using the UAA internal user store for authentication. Deployments enabled for integration via SAML or LDAP are not affected. | ||||||||||||
CVSS v3 Severity: | 3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.2 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-640 | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2015-3189 Source: XF Type: UNKNOWN cloudfoundry-cve20153189-weak-security(127017) Source: CCN Type: Pivotal Web site CVE-2015-3189 - Expire old reset password links Source: CONFIRM Type: Vendor Advisory https://pivotal.io/security/cve-2015-3189 Source: CCN Type: Cloud Foundry Web site Cloud Application Platform - Devops Platform | Cloud Foundry | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |