{"id":"GHSA-8v97-gv3g-32rf","summary":"UAA privilege escalation across identity zones","details":"Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.","aliases":["CVE-2018-1262"],"modified":"2024-12-07T05:40:29.561806Z","published":"2022-05-13T01:07:03Z","database_specific":{"cwe_ids":[],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2024-03-01T23:42:45Z","nvd_published_at":"2018-05-15T20:29:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2018-1262"},{"type":"WEB","url":"https://github.com/cloudfoundry/uaa/commit/14c745aa293b8d3ce9cdd6bfbc6c0ef3f269b21"},{"type":"WEB","url":"https://github.com/cloudfoundry/uaa/commit/dccd3962f969913996ee88f653fce3b108c0205"},{"type":"PACKAGE","url":"https://github.com/cloudfoundry/uaa"},{"type":"WEB","url":"https://www.cloudfoundry.org/blog/cve-2018-1262"}],"affected":[{"package":{"name":"org.cloudfoundry.identity:cloudfoundry-identity-server","ecosystem":"Maven","purl":"pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.12.0"},{"fixed":"4.12.2"}]}],"versions":["4.12.0","4.12.1"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8v97-gv3g-32rf/GHSA-8v97-gv3g-32rf.json"}},{"package":{"name":"org.cloudfoundry.identity:cloudfoundry-identity-server","ecosystem":"Maven","purl":"pkg:maven/org.cloudfoundry.identity/cloudfoundry-identity-server"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.13.0"},{"fixed":"4.13.4"}]}],"versions":["4.13.0","4.13.1","4.13.3"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-8v97-gv3g-32rf/GHSA-8v97-gv3g-32rf.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}