Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2019-3798: Escalation of Privileges in Cloud Controller

CVE-2019-3798: Escalation of Privileges in Cloud Controller




Cloud Foundry Foundation

Affected Cloud Foundry Products and Versions

  • CAPI-Release
    • All versions prior to 1.79.0


Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the victim by creating a client with a name equal to the guid of their victim.


To tell if your system was exploited, run the following in the uaadb:

select client_id, oauth_client_details.authorities from oauth_client_details join users on oauth_client_details.client_id =;

If results are returned with authorities including or cloud_controller.write the vulnerability was likely exploited.


UAA admins should be wary of requests to create clients with guid-shaped client_ids and cloud_controller authorities.

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • CAPI
    • Upgrade All versions to 1.79.0 or greater


2019-04-11: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR