Description
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2959 | Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess. |
References
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T04:19:01.006Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11270
No data.
Status : Modified
Published: 2019-08-05T17:15:10.820
Modified: 2024-11-21T04:20:49.487
Link: CVE-2019-11270
No data.
OpenCVE Enrichment
No data.
EUVD