CVE Database
/

CVE-2019-11282

Back to search

CVE-2019-11282

Published: Oct 23, 2019

Modified: Sep 16, 2024

PUBLISHED

CVSS v3.0

4.3

MEDIUM

Description

Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.

VendorProductVersions

Cloud Foundry

UAA Release

affected
All - < v74.3.0

Cloud Foundry

CF Deployment

affected
All - < v12.2.0

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now