3.9
CVE-2024-38806
- EPSS 0.02%
- Published 18.07.2024 19:15:12
- Last modified 21.11.2024 09:26:50
- Source security@vmware.com
- Teams watchlist Login
- Open Login
Failure to properly synchronize user's permissions in UAA in Cloud Foundry Foundation v40.17.0 https://github.com/cloudfoundry/cf-deployment/releases/tag/v40.17.0 , potentially resulting in users retaining access rights they should not have. This can allow them to perform operations beyond their intended permissions.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
This information is available to logged-in users. Login
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
Vendorn/a
≫
Product
UAA
Default Statusunaffected
Version
v77.10.0 and below
Status
affected
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.02% | 0.043 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
security@vmware.com | 3.9 | 0.5 | 3.4 |
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
|
CWE-440 Expected Behavior Violation
A feature, API, or function does not perform according to its specification.