CVE-2018-1262: Cloudfoundry Cf-Deployment

High severity, CVSS 7.2. EPSS: 1.3% chance of exploitation in the next 30 days.

Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.

Affected products

  • Cloudfoundry Cf-Deployment: from 1.27.0, up to and including 1.31.0
  • Pivotal Software Cloud Foundry Uaa: version 4.12.0 only; version 4.12.1 only; version 4.12.2 only; version 4.13.0 only; version 4.13.1 only; version 4.13.2 only; …
  • Pivotal Software Cloud Foundry Uaa-Release: version 57 only; version 57.1 only; version 58 only

Published 2018-05-15. Last modified 2026-06-17.