Loading
Generated remediation guidance and an executive summary. No account required.
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.
Use CWE-77, Cloudfoundry vendor hub and Uaa Release product page to widen CVE-2019-11279 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-3801, CVE-2019-3788 and CVE-2019-3775 for nearby disclosures in the same product family.