Pivotal Cloud Foundry UAA CVE-2019-3775 Authorization Bypass Vulnerability
BID:107421
Info
Pivotal Cloud Foundry UAA CVE-2019-3775 Authorization Bypass Vulnerability
| Bugtraq ID: | 107421 |
| Class: | Access Validation Error |
| CVE: |
CVE-2019-3775 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 26 2019 12:00AM |
| Updated: | Feb 26 2019 12:00AM |
| Credit: | Daniel Le Gall of SCRT |
| Vulnerable: |
Pivotal Cloud Foundry UAA 66.0 Pivotal Cloud Foundry UAA 64.0 Pivotal Cloud Foundry UAA 63.0 Pivotal Cloud Foundry UAA 62.0 Pivotal Cloud Foundry UAA 61.0 Pivotal Cloud Foundry UAA 60.0 |
| Not Vulnerable: |
Pivotal Cloud Foundry UAA 70.0 |
Discussion
Pivotal Cloud Foundry UAA CVE-2019-3775 Authorization Bypass Vulnerability
Pivotal Cloud Foundry UAA is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Cloud Foundry UAA 70.0 are vulnerable.
Pivotal Cloud Foundry UAA is prone to a security-bypass vulnerability.
An attacker can exploit this issue to bypass certain security restrictions and perform unauthorized actions; this may aid in launching further attacks.
Versions prior to Cloud Foundry UAA 70.0 are vulnerable.
Exploit / POC
Pivotal Cloud Foundry UAA CVE-2019-3775 Authorization Bypass Vulnerability
An attacker can exploit this issue using a readily available tools.
An attacker can exploit this issue using a readily available tools.
References
Pivotal Cloud Foundry UAA CVE-2019-3775 Authorization Bypass Vulnerability
References:
References:
- Cloud Foundry Homepage (Cloud Foundry Foundation)
- CVE-2019-3775: UAA allows users to modify their own email address (Pivotal)