CVE-2016-5016
Last modified
CVE-2016-5016 is a vulnerability of currently unknown severity. Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.. EPSS estimates a 1.03% chance of exploitation in the next 30 days.
Description
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Cloud Foundry | <= 239 |
| Pivotal Software | Cloud Foundry Elastic Runtime | >= 1.6.0, < 1.6.35 |
| Pivotal Software | Cloud Foundry Elastic Runtime | >= 1.7.0, < 1.7.13 |
| Pivotal Software | Cloud Foundry Uaa | <= 3.4.1 |
| Pivotal Software | Cloud Foundry Uaa-Release | <= 12.2 |
References
- https://github.com/cloudfoundry/cf-release/releases/tag/v240Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.4.2Release Notes, Third Party Advisory
- https://pivotal.io/security/cve-2016-5016Vendor Advisory
- https://github.com/cloudfoundry/cf-release/releases/tag/v240Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3Release Notes, Third Party Advisory
- https://github.com/cloudfoundry/uaa/releases/tag/3.4.2Release Notes, Third Party Advisory
- https://pivotal.io/security/cve-2016-5016Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-5016?
How severe is CVE-2016-5016?
How do I fix CVE-2016-5016?
Are you affected by CVE-2016-5016?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
