« Volver al listado

CVE-2019-11270

Estado: ModificadaAlta (7.5)—

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (3)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2019-11270",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@pivotal.io",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.0",
          "baseScore": 7.3,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:R/S:C/C:H/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "HIGH",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.8,
        "exploitabilityScore": 1
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@pivotal.io",
      "affectedData": [
        {
          "vendor": "Cloud Foundry",
          "product": "UAA Release (OSS)",
          "versions": [
            {
              "status": "affected",
              "version": "prior to v73.4.0"
            }
          ]
        }
      ]
    }
  ],
  "published": "2019-08-05T17:15:10.820",
  "references": [
    {
      "url": "https://pivotal.io/security/cve-2019-11270",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@pivotal.io"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2019-11270",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@pivotal.io"
    },
    {
      "url": "https://pivotal.io/security/cve-2019-11270",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2019-11270",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@pivotal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-732"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess."
    },
    {
      "lang": "es",
      "value": "Cloud Foundry UAA versiones anteriores a v73.4.0, contienen una vulnerabilidad en la que un cliente malicioso bajo posesión de la autoridad o el alcance \"clients.write\" puede omitir las restricciones impuestas a los clientes creados por medio de \"clients.write\" y crear clientes con alcances arbitrarios que no poseen."
    }
  ],
  "lastModified": "2026-06-17T02:12:38.683",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EA028AB4-A389-41D4-997B-23DD70DC3025",
              "versionEndExcluding": "2.3.15",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9103B5F4-870C-4629-871D-25DB2C96E6C6",
              "versionEndExcluding": "2.4.11",
              "versionStartIncluding": "2.4.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF7BA0B1-9C33-42F1-8ACA-6AE2EAC13F5B",
              "versionEndExcluding": "2.5.7",
              "versionStartIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C687BD70-0109-4798-9B9D-C7BD35D601D5",
              "versionEndExcluding": "2.6.2",
              "versionStartIncluding": "2.6.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D95746D-026A-4B5A-BEDF-3218F10AF7F0",
              "versionEndExcluding": "73.4.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "AA8501AB-24B2-4A92-AEDD-2EE7CD852DB5",
              "versionEndExcluding": "2.3.22",
              "versionStartIncluding": "2.3.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "CB30A404-6A76-4226-A224-12B6A8131A38",
              "versionEndExcluding": "2.4.16",
              "versionStartIncluding": "2.4.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F0C15A4-76D8-4740-B5F6-70607C83A5DA",
              "versionEndExcluding": "2.5.10",
              "versionStartIncluding": "2.5.0"
            },
            {
              "criteria": "cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F0AF17FF-40DC-4FC6-B89B-4AE8C1372FD8",
              "versionEndExcluding": "2.6.4",
              "versionStartIncluding": "2.6.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@pivotal.io"
}