Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:NPivotal Software Application Service
APPPivotal Software2.3.0 – 2.3.15 (excl.)2.4.0 – 2.4.11 (excl.)2.5.0 – 2.5.7 (excl.)2.6.0 – 2.6.2 (excl.)Pivotal Software Cloud Foundry Uaa
APPPivotal Software< 73.4.0Pivotal Software Operations Manager
APPPivotal Software2.3.0 – 2.3.22 (excl.)2.4.0 – 2.4.16 (excl.)2.5.0 – 2.5.10 (excl.)2.6.0 – 2.6.4 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2019-3793CRITICAL9.8PL ✓same product
Pivotal Apps Manager — przechwycenie danych uwierzytelniających przez niezaszyfrowane HTTP
CVE-2018-15761CRITICAL9.9PL ✓same product
Privilege escalation w Cloud Foundry UAA poprzez manipulację stroną zgody
CVE-2018-15762CRITICAL9.0PL ✓same product
Pivotal Operations Manager — privilege escalation przez nieprawidłowe zarządzanie uprawnieniami
CVE-2015-5171CRITICAL9.8PL ✓same product
Cloud Foundry: brak unieważniania sesji po zmianie hasła
CVE-2015-5172CRITICAL9.8PL ✓same product
Cloud Foundry: brak wygasania linków resetowania hasła