CVE-2019-11268: Pivotal Software Cloud Foundry Uaa-Release
Medium severity, CVSS 4.3. EPSS: 1% chance of exploitation in the next 30 days.
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other identity zones.
Affected products
- Pivotal Software Cloud Foundry Uaa-Release: before 73.3.0 (fixed in 73.3.0)
Published 2019-07-11. Last modified 2026-06-17.