PT-2019-16727 · Cloud Foundry · Cloud Foundry Cloud Controller
Publicado
2019-04-17
·
Atualizado
2019-10-09
·
CVE-2019-3798
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller API Release versions prior to 1.79.0
Description
The issue concerns improper authentication in the validation of user permissions. A remote authenticated malicious user, with the ability to create UAA clients and knowledge of a victim's email, may escalate their privileges to those of the victim. This is achieved by creating a client with a name equal to the guid of the victim.
Recommendations
For versions prior to 1.79.0, update to version 1.79.0 or later to resolve the issue.
Correção
Improper Authentication
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloud Foundry Cloud Controller