-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The commit diff shows removal of sessionId handling from UaaAuthenticationDetails.toString() method. The vulnerability stemmed from session IDs being included in audit logs via this toString() implementation. The added test explicitly verifies sessionId exclusion from logs, confirming this was the vulnerable path. No other functions show sessionID handling in the provided diffs.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.cloudfoundry.identity:cloudfoundry-identity-server | maven | < 4.5.5 | 4.5.5 |
| org.cloudfoundry.identity:cloudfoundry-identity-server | maven | >= 4.6.0, < 4.7.4 | 4.7.4 |
| org.cloudfoundry.identity:cloudfoundry-identity-server | maven | >= 4.8.0, < 4.8.3 | 4.8.3 |
KEV Misses 88% of Exploited CVEs- Get the report