CVE-2019-3775: UAA allows users to modify their own email address.
Cloud Foundry Foundation
Affected Cloud Foundry Products and Versions
- UAA release:
- all versions prior to v70.0
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
Users of affected versions should apply the following mitigations or upgrades:
- UAA release v70.0
This issue was responsibly reported by Daniel Le Gall of SCRT.
2019-02-26: Initial vulnerability report published.