CVE-2015-5172

CRITICAL9.8EPSS 0.40%

Cloud Foundry Runtime has Weak Password Recovery Mechanism for Forgotten Password

Published: 5/13/2022Modified: 2/28/2024
Also known as:GHSA-cq6m-74r4-x77g

Description

Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1CRITICAL9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References (4)