CVE-2019-3775Authentication Bypass by Spoofing in Foundry UAA Release

Severity
6.5MEDIUMNVD
CNA7.1
EPSS
0.1%
top 67.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 7
Latest updateMay 13

Description

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5cloud_foundry/uaa_releaseAllv70.0

🔴Vulnerability Details

2
GHSA
GHSA-hwg9-rc2h-c2p3: Cloud Foundry UAA, versions prior to v702022-05-13
CVEList
UAA allows users to modify their own email address2019-03-07

💬Community

2
Bugzilla
CVE-2019-13721 chromium-browser: use-after-free in PDFium2019-11-04
Bugzilla
CVE-2019-13720 chromium-browser: use-after-free in audio2019-11-04
CVE-2019-3775 — Authentication Bypass by Spoofing | cvebase