CVE-2019-11270: Pivotal Software Application Service
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
Affected products
- Pivotal Software Application Service: from 2.3.0, before 2.3.15 (fixed in 2.3.15); from 2.4.0, before 2.4.11 (fixed in 2.4.11); from 2.5.0, before 2.5.7 (fixed in 2.5.7); from 2.6.0, before 2.6.2 (fixed in 2.6.2)
- Pivotal Software Cloud Foundry Uaa: before 73.4.0 (fixed in 73.4.0)
- Pivotal Software Operations Manager: from 2.3.0, before 2.3.22 (fixed in 2.3.22); from 2.4.0, before 2.4.16 (fixed in 2.4.16); from 2.5.0, before 2.5.10 (fixed in 2.5.10); from 2.6.0, before 2.6.4 (fixed in 2.6.4)
Published 2019-08-05. Last modified 2026-06-17.