CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: pivotal

Published: 2019-09-26T21:11:24.033285Z

Updated: 2024-09-16T23:51:53.473Z

Reserved: 2019-04-18T00:00:00

Link: CVE-2019-11278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-09-26T21:15:10.933

Modified: 2020-10-05T02:06:27.597

Link: CVE-2019-11278

cve-icon Redhat

No data.