pivotalsoftware application-service CVE-2019-11270 vulnerability in Pivotal Software Products
Published on August 5, 2019

UAA clients.write vulnerability
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.

NVD

Weakness Type

Improper Privilege Management

The software does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.


Products Associated with CVE-2019-11270

You can be notified by email with stack.watch whenever vulnerabilities like CVE-2019-11270 are published in these products:

 
 
 

Affected Versions

Cloud Foundry UAA Release (OSS) Version prior to v73.4.0 is affected by CVE-2019-11270

Exploit Probability

EPSS
0.23%
Percentile
45.40%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.