CVE-2016-5016

Description

Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.

Risk Information

Base Score
5.9
MODERATE
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
EPSS Score
Exploitation Probability
0.278

Associated Vulnerability

VulnerabilityOS Platform
Vulnerabilities CVE-2016-5016 are fixed in Cloudfoundry-identity-server 3.3.0.3Windows
Vulnerabilities CVE-2016-5016 are fixed in Cloudfoundry-identity-server 3.4.2Windows
Vulnerabilities CVE-2016-5016 are fixed in Cloudfoundry-identity-server for Linux 3.3.0.3Linux
Vulnerabilities CVE-2016-5016 are fixed in Cloudfoundry-identity-server for Linux 3.4.2Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234