Loading
Generated remediation guidance and an executive summary. No account required.
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should not have.
Use CWE-77, Cloudfoundry vendor hub and User Account And Authentication product page to widen CVE-2019-11278 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2020-5402, CVE-2016-0732 and CVE-2021-22001 for nearby disclosures in the same product family.