PT-2019-12218 · Cloud Foundry · Cloud Foundry Uaa

Yuval Avrahami

·

Published

2019-08-05

·

Updated

2020-10-02

·

CVE-2019-11270

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry UAA versions prior to 73.4.0
Description The issue allows a malicious client with the clients.write authority or scope to bypass restrictions and create clients with arbitrary scopes that the creator does not possess. This can lead to privilege escalation.
Recommendations For Cloud Foundry UAA versions prior to 73.4.0, update to version 73.4.0 or later to resolve the issue. As a temporary workaround, consider restricting the clients.write authority or scope to minimize the risk of exploitation. Restrict access to client creation via clients.write to prevent malicious clients from bypassing restrictions.

Fix

Incorrect Permission

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11270

Affected Products

Cloud Foundry Uaa