CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
Advisories
Source ID Title
EUVD EUVD EUVD-2019-2966 CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: pivotal

Published:

Updated: 2024-09-16T23:51:53.473Z

Reserved: 2019-04-18T00:00:00

Link: CVE-2019-11278

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-09-26T21:15:10.933

Modified: 2024-11-21T04:20:50.370

Link: CVE-2019-11278

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.