Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
18 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.23% | — | Cloudfoundry Cf-deploymentCloudfoundry Uaa-release | 5/3/2026 | 17/6/2026 | Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0. | |
| Analizada | Alta (7.5) | 0.20% | — | Cloudfoundry Cf-deploymentCloudfoundry UAA Release | 13/5/2025 | 17/6/2026 | Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. | |
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry UAA Release | 26/9/2019 | 17/6/2026 | CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls. | |
| Modificada | Media (4.3) | 1.0% | — | Pivotal Software Cloud Foundry Uaa-release | 11/7/2019 | 17/6/2026 | Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other… | |
| Modificada | Alta (8.8) | 1.1% | — | Pivotal Software Cloud Foundry Uaa-release | 19/6/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially… | |
| Modificada | Crítica (9.8) | 0.59% | — | Cloudfoundry Cf-deploymentCloudfoundry CredhubCloudfoundry UAA Release | 25/4/2019 | 17/6/2026 | Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component. | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry UAA Release | 25/4/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim. | |
| Modificada | Media (6.5) | 0.88% | — | Cloudfoundry UAA Release | 7/3/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. | |
| Modificada | Alta (8.8) | 1.8% | — | Pivotal Software Cloud Foundry Uaa-release | 13/12/2018 | 17/6/2026 | Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of… | |
| Modificada | Alta (8.8) | 1.7% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloudfoundry UAA Release | 19/11/2018 | 17/6/2026 | Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pivotal Software Cloudfoundry UAAPivotal Software Cloudfoundry UAA Release | 5/10/2018 | 17/6/2026 | Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user. | |
| Modificada | Media (6.1) | 0.85% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release | 25/6/2018 | 17/6/2026 | Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote… | |
| Modificada | Alta (7.2) | 1.3% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releaseCloudfoundry Cf-deployment | 15/5/2018 | 17/6/2026 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the… | |
| Modificada | Alta (8.8) | 1.0% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releasePivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry Cf-deployment | 1/2/2018 | 17/6/2026 | In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the… | |
| Modificada | Media (5.3) | 1.1% | — | Cloudfoundry Cf-releaseCloudfoundry Uaa-release | 27/11/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same… | |
| Modificada | Alta (8.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime | 7/9/2017 | 17/6/2026 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations… | |
| Modificada | Alta (8.1) | 0.90% | — | Pivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect… | |
| Modificada | Media (5.9) | 1.0% | — | Pivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release | 24/4/2017 | 17/6/2026 | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired. |