High
CVSS score: 9.2 (Critical) CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS score: 9.0 Critical) (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H)
Vendor
CloudFoundry Foundation
Versions Affected
*Severity is Critical unless otherwise noted.
UAA
– All versions through v77.30.0 (inclusive)
cf-deployment
– All versions through v48.9.0 (inclusive)
Description
A user authenticating through a federated OIDC provider can be granted the `uaa.admin` scope even when the operator has restricted that provider to a narrow scope prefix via `externalGroupsWhitelist`.
Preconditions
– An OIDC identity provider configured with `groupMappingMode: AS_SCOPES` and a wildcard `externalGroupsWhitelist` entry.
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below.
The Cloud Foundry project recommends upgrading the following releases:
Uaa
– Upgrade UAA version to v77.31.0 or greater
cf-deployment
– Upgrade cf-deployment version to v48.10.0 or greater
Credit
This issue was responsibly reported by Tanzu at Broadcom
History
Initial vulnerability report published.
