CVE Vulnerabilities

CVE-2019-11270

Improper Privilege Management

Published: Aug 05, 2019 | Modified: Nov 21, 2024
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the clients.write authority or scope can bypass the restrictions imposed on clients created via clients.write and create clients with arbitrary scopes that the creator does not possess.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Application_service Pivotal_software 2.3.0 (including) 2.3.15 (excluding)
Application_service Pivotal_software 2.4.0 (including) 2.4.11 (excluding)
Application_service Pivotal_software 2.5.0 (including) 2.5.7 (excluding)
Application_service Pivotal_software 2.6.0 (including) 2.6.2 (excluding)
Cloud_foundry_uaa Pivotal_software * 73.4.0 (excluding)
Operations_manager Pivotal_software 2.3.0 (including) 2.3.22 (excluding)
Operations_manager Pivotal_software 2.4.0 (including) 2.4.16 (excluding)
Operations_manager Pivotal_software 2.5.0 (including) 2.5.10 (excluding)
Operations_manager Pivotal_software 2.6.0 (including) 2.6.4 (excluding)

Potential Mitigations

References