CVE-2016-5016
Summary
| CVE | CVE-2016-5016 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-04-24 19:59:00 UTC |
| Updated | 2019-02-26 17:18:00 UTC |
| Description | Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 does not validate if a certificate is expired. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Cloud Foundry | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Elastic Runtime | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Elastic Runtime | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Uaa | All | All | All | All |
| Application | Pivotal Software | Cloud Foundry Uaa-release | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Release Updated to UAA 3.4.2 · cloudfoundry/uaa-release · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| CVE-2016-5016 UAA accepts expired certificates | Security | VMware Tanzu | CONFIRM | pivotal.io | Vendor Advisory |
| Release v240 · cloudfoundry-attic/cf-release · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release Updated to UAA 3.3.0.3 · cloudfoundry/uaa-release · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release UAA 3.4.2 - Security Release (CVE-2016-5016) · cloudfoundry/uaa · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release UAA 3.3.0.3 - Security Release (CVE-2016-5016) · cloudfoundry/uaa · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| Release UAA 2.7.4.6 - Security Release (CVE-2016-5016) · cloudfoundry/uaa · GitHub | CONFIRM | github.com | Release Notes, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.