VYPR
Unrated severityNVD Advisory· Published Oct 5, 2018· Updated Sep 17, 2024

Cloud Foundry UAA MFA does not prevent brute force of MFA code

CVE-2018-11082

Description

Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.

Affected products

2
  • Range: all versions
  • Cloud Foundry/UAA Releasev5
    Range: all versions

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.