CVE-2018-1192: Pivotal Software Cloud Foundry Cf-Deployment

High severity, CVSS 8.8. EPSS: 1% chance of exploitation in the next 30 days.

In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the SessionID is logged in audit event logs. An attacker can use the SessionID to impersonate a logged-in user.

Affected products

  • Pivotal Software Cloud Foundry Cf-Deployment: before 1.7 (fixed in 1.7)
  • Pivotal Software Cloud Foundry Cf-Release: before 285 (fixed in 285)
  • Pivotal Software Cloud Foundry Uaa: from 4.5.0, before 4.5.5 (fixed in 4.5.5); from 4.7.0, before 4.7.4 (fixed in 4.7.4); from 4.8.0, before 4.8.3 (fixed in 4.8.3)
  • Pivotal Software Cloud Foundry Uaa-Release: version 45.7 only; version 52.7 only; version 53.3 only

Published 2018-02-01. Last modified 2026-06-17.