CVE-2019-3798
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.34%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the victim by creating a client with a name equal to the guid of their victim.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.34% probability · 70th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- cloudfoundry/capi-release
- Source
- security_alert@emc.com
References
- http://www.securityfocus.com/bid/108095Third Party Advisory, VDB Entry
- https://www.cloudfoundry.org/blog/cve-2019-3798Vendor Advisory
- http://www.securityfocus.com/bid/108095Third Party Advisory, VDB Entry
- https://www.cloudfoundry.org/blog/cve-2019-3798Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.