CVE Vulnerabilities

CVE-2019-11279

Published: Sep 26, 2019 | Modified: Oct 05, 2020
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
6.5 MEDIUM
AV:N/AC:L/Au:S/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldnt be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

Affected Software

Name Vendor Start Version End Version
Uaa_release Cloudfoundry * 74.1.0 (excluding)

References