Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
2019-03-07T18:29:00.367
2024-11-21T04:42:30.500
Modified
CVSSv3.0: 7.1 (HIGH)
AV:N/AC:L/Au:S/C:N/I:P/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | uaa_release | < 70.0 | Yes |