CVE-2019-11279: Cloudfoundry Uaa Release
High severity, CVSS 8.8. EPSS: 1.3% chance of exploitation in the next 30 days.
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.
Affected products
- Cloudfoundry Uaa Release: before 74.1.0 (fixed in 74.1.0)
Published 2019-09-26. Last modified 2026-06-17.