PT-2019-12228 · Cloud Foundry · Cloud Foundry Uaa
Amit Laish
·
Published
2019-10-23
·
Updated
2021-08-17
·
CVE-2019-11282
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry UAA versions prior to 74.3.0
Description
The issue concerns an endpoint vulnerable to SCIM injection attack. A remote authenticated malicious user with
scim.invite scope can craft a request with malicious content, potentially leaking information about users of the UAA.Recommendations
For versions prior to 74.3.0, update to version 74.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the
scim.invite scope to minimize the risk of exploitation.Fix
Special Elements Injection
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Foundry Uaa