CVE-2019-3798Improper Authentication in Foundry Capi-release

Severity
7.5HIGHNVD
CNA6.0
EPSS
1.9%
top 16.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 17
Latest updateMay 13

Description

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the victim by creating a client with a name equal to the guid of their victim.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9

Affected Packages2 packages

CVEListV5cloud_foundry/capi-releaseAll1.79.0

🔴Vulnerability Details

2
GHSA
GHSA-9hx4-42jp-5rgc: Cloud Foundry Cloud Controller API Release, versions prior to 12022-05-13
CVEList
Escalation of Privileges in Cloud Controller2019-04-17
CVE-2019-3798 — Improper Authentication | cvebase