Pivotal Software Cloud Foundry UAA-release 62.0

CPE Details

Pivotal Software Cloud Foundry UAA-release 62.0
62.0
2019-07-15
10h51 +00:00
2019-07-15
10h51 +00:00
Alerte pour un CPE
Restez informé de toutes modifications pour un CPE spécifique.
Gestion des notifications

CPE Name: cpe:2.3:a:pivotal_software:cloud_foundry_uaa-release:62.0:*:*:*:*:*:*:*

Informations

Vendor

pivotal_software

Product

cloud_foundry_uaa-release

Version

62.0

Related CVE

Open and find in CVE List

CVE ID Publié Description Score Gravité
CVE-2019-11268 2019-07-11 18h11 +00:00 Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.
4.3
Moyen
CVE-2019-3787 2019-06-19 22h28 +00:00 Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the attacker to gain complete control of the user's account.
8.8
Haute
CVE-2018-15754 2018-12-13 22h00 +00:00 Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of the same username in the other identity provider.
8.8
Haute