CVE-2018-15759

Source
https://cve.org/CVERecord?id=CVE-2018-15759
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-15759.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-15759
Published
2018-11-19T14:29:00.343Z
Modified
2025-12-08T18:59:35.092303Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Pivotal Cloud Foundry On Demand Services SDK, versions prior to 0.24 contain an insecure method of verifying credentials. A remote unauthenticated malicious user may make many requests to the service broker with different credentials, allowing them to infer valid credentials and gain access to perform broker operations.

References

Affected packages

Git / github.com/pivotal-cf/brokerapi

Affected ranges

Type
GIT
Repo
https://github.com/pivotal-cf/brokerapi
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v1.*
v1.0.0
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.0.3
v2.0.4
v2.0.5
v3.*
v3.0.0
v3.0.1

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-15759.json"

Git / github.com/pivotal-cf/on-demand-services-sdk

Affected ranges

Type
GIT
Repo
https://github.com/pivotal-cf/on-demand-services-sdk
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed

Affected versions

v0.*
v0.10.0
v0.10.1
v0.11.0
v0.12.0
v0.12.1
v0.12.3
v0.12.4
v0.13.0
v0.14.0
v0.14.1
v0.15.0
v0.15.0-alpha-1
v0.15.0-alpha-2
v0.15.0-pre-alpha-1
v0.15.0-rc-1
v0.15.1
v0.15.2
v0.15.3
v0.16.0
v0.16.1
v0.17.0
v0.17.0-alpha1
v0.17.1
v0.17.1-alpha1
v0.17.2
v0.17.3-alpha1
v0.18.0
v0.18.0-alpha-1
v0.19.0
v0.20.0
v0.20.0-alpha.1
v0.20.0-alpha.2
v0.21.0
v0.21.0-alpha.1
v0.21.0-alpha.2
v0.21.1
v0.21.2
v0.22.0
v0.22.0-alpha.1
v0.22.0-alpha2
v0.23.0
v0.3.0
v0.4.0
v0.5.0
v0.6.0
v0.7.0
v0.8.0
v0.9.0

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-15759.json"