CVE-2019-11282Sensitive Information Exposure in Foundry CF Deployment

Severity
4.3MEDIUMNVD
EPSS
0.3%
top 46.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 23
Latest updateMay 24

Description

Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages4 packages

CVEListV5cloud_foundry/uaa_releaseAllv74.3.0
CVEListV5cloud_foundry/cf_deploymentAllv12.2.0

🔴Vulnerability Details

2
GHSA
GHSA-9jcx-c729-r5q2: Cloud Foundry UAA, versions prior to v742022-05-24
CVEList
UAA is vulnerable to a Blind SCIM injection leading to information disclosure2019-10-23
CVE-2019-11282 — Sensitive Information Exposure | cvebase