First published: Fri Aug 09 2019(Updated: )
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
Credit: security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry User Account And Authentication | <74.0.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11274 is a vulnerability in Cloud Foundry UAA versions prior to 74.0.0 that allows for an XSS attack.
An unauthenticated attacker can craft a URL with a malicious SCIM filter that contains JavaScript, which older browsers may execute.
CVE-2019-11274 has a severity rating of medium (6.1).
To fix CVE-2019-11274, update Cloud Foundry UAA to version 74.0.0 or later.
Yes, you can find more information about CVE-2019-11274 at the following link: https://www.cloudfoundry.org/blog/cve-2019-11274