{"id":"CVE-2018-15761","details":"Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.","aliases":["GHSA-292x-hjr8-226f"],"modified":"2026-07-08T17:15:45.387676Z","published":"2018-11-19T14:29:00.467Z","references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2018-15761/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa","events":[{"introduced":"0"},{"fixed":"206e2a3a8a08bf89cf46a0c65ed43bf0514b1826"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.23.0"}]}}],"versions":["4.22.0","4.19.0","4.21.0","4.20.0","4.18.0","4.17.0","4.16.0","releases/4.15.0","4.15.0","4.12.0","4.11.0","4.10.0","4.9.0","travis-success-1497","travis-success-1478","travis-success-1475","1.8.0","1.6.2","1.6.1","1.5.4.1","1.5.4","1.5.3","1.5.2.1","1.5.2","1.5.0","1.4.7","1.4.6","1.4.5","1.4.3","1.4.2","1.4.1","1.4.0","1.2.6","1.2.0","1.1.2","1.1.1","1.1","1.0.3","1.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-15761.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa-release","events":[{"introduced":"0"},{"fixed":"f34df0ec7b065d4f9de2c952e117df1b7f1134b8"}],"database_specific":{"cpe":"cpe:2.3:a:pivotal_software:cloudfoundry_uaa_release:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"64.0"}],"source":"CPE_RANGE"}}],"versions":["v63.0","v62.0","v61.0","v60","v55","v59","v58","v57","v56","v53","v31","v27","v26","v24","v25","v23","v22","v21","v20","v19","v18","v17","v16","v15","v14","v12.3","ci-upgrade","v12","v11","v10","v9","v8","v7","v6","v3","v2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-15761.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}