Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-11279

Опубликовано: 26 сент. 2019
Источник: nvd
CVSS3: 8.7
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*
Версия до 74.1.0 (исключая)

EPSS

Процентиль: 65%
0.00494
Низкий

8.7 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
NVD-CWE-Other

Связанные уязвимости

CVSS3: 8.8
github
около 3 лет назад

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.

EPSS

Процентиль: 65%
0.00494
Низкий

8.7 High

CVSS3

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-77
NVD-CWE-Other