CloudFoundry Foundation UAA是CloudFoundry Foundation基金会的一个身份认证和用户账户管理平台。 CloudFoundry Foundation UAA 78.13.0之前版本存在加密问题漏洞,该漏洞源于UAA与LDAP目录之间的证书身份验证问题,可能导致网络攻击者冒充目录,获取LDAP绑定密码和用户密码,并返回伪造的组成员身份以授予管理员权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| CloudFoundry Foundation | Cf-deployment | < 56.2.0 |
affected |
| CloudFoundry Foundation | UAA | < 78.13.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| CloudFoundry Foundation | UAA | 0 ~ 78.13.0 | - |
|
| CloudFoundry Foundation | Cf-deployment | 0 ~ 56.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-47829 | Argument Injection in BOSH CLI Allows Local Command Execution on Operator Workstations via | |
| CVE-2026-47826 | blobs.yaml Path Traversal Allows File Writes |
No comments yet