CyberRota Analysis
This is a high severity vulnerability with a CVSS score of 8.8. See the original NVD description below for full technical details.
CVE
CVE-2018-1195
Severity
HIGH
CVSS
8.8
EPSS
0.99%
Original NVD Description
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an access token, either due to lack of client credentials or revocation, would allow authentication.
Related CVEs
Other vulnerabilities affecting the same vendor(s)