PT-2019-16717 · Cloud Foundry · Cloud Foundry Uaa
Kristian Kraljic
·
Publicado
2019-06-19
·
Atualizado
2020-02-10
·
CVE-2019-3787
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry UAA versions prior to 73.0.0
Description
The issue allows for potential account takeover through password recovery emails sent to a potentially fraudulent address. When a user's email address is not provided and the username does not contain an @ character, the system appends "unknown.org" to the email address. Since "unknown.org" is held by a private company, this creates an attack vector.
Recommendations
For versions prior to 73.0.0, update to version 73.0.0 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cloud Foundry Uaa