Vulnerability CVE-2019-11268


Published: 2019-07-11

Description:
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.

Type:

CWE-200

(Information Exposure)

Vendor: Pivotal software
Product: Cloud foundry uaa-release 
Version:
9
8
73.0.0
72.0
71.0
70.0
7
69.0
68.0
67.0
66.0
64.0
63.0
62.0
61.0
60.2
60
6
59
58.1
58
57.4
57.3
57.2
57.1
57
56
55.2
55.1
55
54
53.3
53.2
53.1
53
52.9
52.8
52.7
52.6
52.5
52.4
52.2
52.10
52
51
50
5
48
45.9
45.8
45.7
45.6
45.5
45.4
45.3
45.2
45.11
45.10
45
44
43
41.1
41
40
4
39
38
37
36
35
34.3
34.2
34.1
34
33
32
31
30.9
30.8
30.7
30.6
30.5
30.4
30.3
30.2
30.1
30
3
29
28
27
26
25
24.9
24.8
24.7
24.6
24.5
See more versions on NVD

CVSS2 => (AV:N/AC:L/Au:S/C:P/I:N/A:N)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
Partial
None
None

 References:
https://www.cloudfoundry.org/blog/cve-2019-11268

Related CVE
CVE-2019-11276
Pivotal Apps Manager, included in Pivotal Application Service versions 2.3.x prior to 2.3.16, 2.4.x prior to 2.4.12, 2.5.x prior to 2.5.8, and 2.6.x prior to 2.6.3, makes a request to the /cloudapplication endpoint via Spring actuator, and subsequent...
CVE-2019-11270
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrar...
CVE-2019-11273
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may...
CVE-2019-3794
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.
CVE-2019-11272
Spring Security, versions 4.2.x up to 4.2.12, and older unsupported versions support plain text passwords using PlaintextPasswordEncoder. If an application using an affected version of Spring Security is leveraging PlaintextPasswordEncoder and a user...
CVE-2019-3787
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending ?unknown.org? to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack v...
CVE-2019-11269
Spring Security OAuth versions 2.3 prior to 2.3.6, 2.2 prior to 2.2.5, 2.1 prior to 2.1.5, and 2.0 prior to 2.0.18, as well as older unsupported versions could be susceptible to an open redirector attack that can leak an authorization code. A malicio...
CVE-2019-3790
The Pivotal Ops Manager, 2.2.x versions prior to 2.2.23, 2.3.x versions prior to 2.3.16, 2.4.x versions prior to 2.4.11, and 2.5.x versions prior to 2.5.3, contain configuration that circumvents refresh token expiration. A remote authenticated user c...

Copyright 2019, cxsecurity.com

 

Back to Top