An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| org.cloudfoundry.identity:cloudfoundry-identity-server(Maven) | 3.10.0 | 3.12.0 | N/A |
| org.cloudfoundry.identity:cloudfoundry-identity-server(Maven) | 0 | 3.9.8 | N/A |
CVSS Metrics