CVE-2015-3189 describes a vulnerability in Cloud Foundry Runtime, UAA Standalone, and Pivotal Cloud Foundry Runtime versions where old password reset links remain valid even after a user changes their email address. This issue, applicable only to deployments using UAA's internal user store, could allow unauthorized access to an account if an attacker gains access to a previously valid reset link. With a CVSS score of 3.7 (LOW), the attack complexity is high, and the potential impact is limited to confidentiality. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 208CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | ||
<= 1.4.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:* | ||
<= 2.2.5CPE matchmatch criteria | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.