Description
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-13418 | Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2019-3787 |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T21:57:57.203Z
Reserved: 2019-01-03T00:00:00.000Z
Link: CVE-2019-3787
No data.
Status : Modified
Published: 2019-06-19T23:15:10.127
Modified: 2024-11-21T04:42:32.550
Link: CVE-2019-3787
No data.
OpenCVE Enrichment
No data.
EUVD