CVE-2019-11270

Publication date

2019-08-05 16:21:54

Family

pivotal

State

PUBLISHED

Description

Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the clients.write authority or scope can bypass the restrictions imposed on clients created via clients.write and create clients with arbitrary scopes that the creator does not possess.