PT-2019-16727 · Cloud Foundry · Cloud Foundry Cloud Controller
Published
2019-04-17
·
Updated
2019-10-09
·
CVE-2019-3798
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller API Release versions prior to 1.79.0
Description
The issue concerns improper authentication in the validation of user permissions. A remote authenticated malicious user, with the ability to create UAA clients and knowledge of a victim's email, may escalate their privileges to those of the victim. This is achieved by creating a client with a name equal to the guid of the victim.
Recommendations
For versions prior to 1.79.0, update to version 1.79.0 or later to resolve the issue.
Fix
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry Cloud Controller