CVE Database
/

CVE-2019-3798

Back to search

CVE-2019-3798

Published: Apr 17, 2019

Modified: Sep 17, 2024

PUBLISHED

CVSS v3.0

6.0

MEDIUM

Description

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the victim by creating a client with a name equal to the guid of their victim.

VendorProductVersions

Cloud Foundry

CAPI-release

affected
All - < 1.79.0

Weaknesses (CWE)

CVSS v3.0 Details

CVSS v3.0 Vector

CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:U/C:L/I:H/A:H

Attack Vector

Network

Attack Complexity

High

Privileges Required

High

User Interaction

Required

Scope

Unchanged

Confidentiality

Low

Integrity

High

Availability

High

References

108095
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now