Lucene search

K
osvGoogleOSV:GHSA-CQ6M-74R4-X77G
HistoryMay 13, 2022 - 1:07 a.m.

Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password

2022-05-1301:07:00
Google
osv.dev
2
cloud foundry
password recovery
security vulnerability

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.8%

Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

AI Score

9.4

Confidence

High

EPSS

0.002

Percentile

64.8%

Related for OSV:GHSA-CQ6M-74R4-X77G