Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired.
References
Link | Resource |
---|---|
https://github.com/cloudfoundry/cf-release/releases/tag/v240 | Release Notes Third Party Advisory |
https://github.com/cloudfoundry/uaa-release/releases/tag/v11.3 | Release Notes Third Party Advisory |
https://github.com/cloudfoundry/uaa-release/releases/tag/v12.3 | Release Notes Third Party Advisory |
https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.6 | Release Notes Third Party Advisory |
https://github.com/cloudfoundry/uaa/releases/tag/3.3.0.3 | Release Notes Third Party Advisory |
https://github.com/cloudfoundry/uaa/releases/tag/3.4.2 | Release Notes Third Party Advisory |
https://pivotal.io/security/cve-2016-5016 | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: redhat
Published: 2017-04-24T19:00:00
Updated: 2017-04-24T18:57:01
Reserved: 2016-05-24T00:00:00
Link: CVE-2016-5016
JSON object: View
NVD Information
Status : Analyzed
Published: 2017-04-24T19:59:00.253
Modified: 2019-02-26T17:18:37.240
Link: CVE-2016-5016
JSON object: View
Redhat Information
No data.
CWE