Lucene search

K
osvGoogleOSV:GHSA-H533-Q6JC-QX28
HistoryMay 13, 2022 - 1:07 a.m.

Cloud Foundry Runtime Insufficient Session Expiration vulnerability

2022-05-1301:07:00
Google
osv.dev
4
cloud foundry
runtime
password change
attackers
session expiration

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

64.8%

The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions.

AI Score

9.3

Confidence

High

EPSS

0.002

Percentile

64.8%

Related for OSV:GHSA-H533-Q6JC-QX28