HIGH🇵🇱 Wersja polska

CVE-2019-11270

CVSS 7.5v3.1pub. 2019-08-05upd. 2024-11-21

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Pivotal Software Application Service

    APP
    Pivotal Software
    2.3.0 – 2.3.15 (excl.)2.4.0 – 2.4.11 (excl.)2.5.0 – 2.5.7 (excl.)2.6.0 – 2.6.2 (excl.)
  • Pivotal Software Cloud Foundry Uaa

    APP
    Pivotal Software
    < 73.4.0
  • Pivotal Software Operations Manager

    APP
    Pivotal Software
    2.3.0 – 2.3.22 (excl.)2.4.0 – 2.4.16 (excl.)2.5.0 – 2.5.10 (excl.)2.6.0 – 2.6.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2019-3793CRITICAL9.8PL ✓same product

Pivotal Apps Manager — przechwycenie danych uwierzytelniających przez niezaszyfrowane HTTP

CVE-2018-15761CRITICAL9.9PL ✓same product

Privilege escalation w Cloud Foundry UAA poprzez manipulację stroną zgody

CVE-2018-15762CRITICAL9.0PL ✓same product

Pivotal Operations Manager — privilege escalation przez nieprawidłowe zarządzanie uprawnieniami

CVE-2015-5171CRITICAL9.8PL ✓same product

Cloud Foundry: brak unieważniania sesji po zmianie hasła

CVE-2015-5172CRITICAL9.8PL ✓same product

Cloud Foundry: brak wygasania linków resetowania hasła