Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
References
Link | Resource |
---|---|
https://pivotal.io/security/cve-2015-5170-5173 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2017-10-24 10:29
Updated : 2021-08-25 14:15
NVD link : CVE-2015-5172
Mitre link : CVE-2015-5172
JSON object : View
CWE
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
Products Affected
pivotal_software
- cloud_foundry_uaa
- cloud_foundry_elastic_runtime
cloudfoundry
- cf-release