Vulnerabilities (CVE)

Filtered by vendor Cloudfoundry Subscribe
Filtered by product Uaa Release
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2019-11279 1 Cloudfoundry 1 Uaa Release 2020-10-05 6.5 MEDIUM 8.8 HIGH
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.