Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2019-3775: UAA allows users to modify their own email address

Severity

High

Vendor

Cloud Foundry Foundation

Affected Cloud Foundry Products and Versions

  • UAA release:
    • all versions prior to v70.0

Description

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.

Mitigation

Users of affected versions should apply the following mitigations or upgrades:

    • UAA release v70.0

Credit

This issue was responsibly reported by Daniel Le Gall of SCRT.

History

2019-02-26: Initial vulnerability report published.

 

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES