CVE-2019-11274: UAA SCIM Filter XSS
Published Aug 9, 2019
·Updated
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute.
Affected Software
1 affected component
cloudfoundry User Account And Authentication<74.0.0
Event History
Aug 9, 2019
CVE Published
via MITRE·07:22 PM
Data Sourced
via MITRE·07:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2019-11274?
CVE-2019-11274 is a vulnerability in Cloud Foundry UAA versions prior to 74.0.0 that allows for an XSS attack.
2
How does CVE-2019-11274 work?
An unauthenticated attacker can craft a URL with a malicious SCIM filter that contains JavaScript, which older browsers may execute.
3
What is the severity of CVE-2019-11274?
CVE-2019-11274 has a severity rating of medium (6.1).
4
How do I fix CVE-2019-11274?
To fix CVE-2019-11274, update Cloud Foundry UAA to version 74.0.0 or later.
5
Are there any references for CVE-2019-11274?
Yes, you can find more information about CVE-2019-11274 at the following link: https://www.cloudfoundry.org/blog/cve-2019-11274