CVE Vulnerabilities

CVE-2019-11270

Improper Privilege Management

Published: Aug 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the clients.write authority or scope can bypass the restrictions imposed on clients created via clients.write and create clients with arbitrary scopes that the creator does not possess.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Application_servicePivotal_software2.3.0 (including)2.3.15 (excluding)
Application_servicePivotal_software2.4.0 (including)2.4.11 (excluding)
Application_servicePivotal_software2.5.0 (including)2.5.7 (excluding)
Application_servicePivotal_software2.6.0 (including)2.6.2 (excluding)
Cloud_foundry_uaaPivotal_software*73.4.0 (excluding)
Operations_managerPivotal_software2.3.0 (including)2.3.22 (excluding)
Operations_managerPivotal_software2.4.0 (including)2.4.16 (excluding)
Operations_managerPivotal_software2.5.0 (including)2.5.10 (excluding)
Operations_managerPivotal_software2.6.0 (including)2.6.4 (excluding)

Potential Mitigations

References