Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
LDAP StartTLS unconditionally disables hostname verification
Vulnerability Description
A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and return forged group memberships that grant themselves admin scopes. This affects every deployment that authenticates users against LDAP over StartTLS. Affected versions: UAA versions prior to v78.13.0; Cf-deployment versions prior to v56.2.0.
CVSS Information
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:N
Vulnerability Type
N/A
Vulnerability Title
CloudFoundry Foundation UAA 加密问题漏洞
Vulnerability Description
CloudFoundry Foundation UAA是CloudFoundry Foundation基金会的一个身份认证和用户账户管理平台。 CloudFoundry Foundation UAA 78.13.0之前版本存在加密问题漏洞,该漏洞源于UAA与LDAP目录之间的证书身份验证问题,可能导致网络攻击者冒充目录,获取LDAP绑定密码和用户密码,并返回伪造的组成员身份以授予管理员权限。
CVSS Information
N/A
Vulnerability Type
N/A