Unrated severityNVD Advisory· Published Oct 23, 2019· Updated Sep 16, 2024
UAA is vulnerable to a Blind SCIM injection leading to information disclosure
CVE-2019-11282
Description
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: <74.3.0
- Cloud Foundry/CF Deploymentv5Range: All
- Cloud Foundry/UAA Releasev5Range: All
Patches
Vulnerability mechanics
References
1- www.cloudfoundry.org/blog/cve-2019-11282mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.