CVE-2019-3775: UAA allows users to modify their own email address
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-3775?
CVE-2019-3775 is a vulnerability in Cloud Foundry UAA that allows a user to impersonate a different user by changing their email address.
What is the severity of CVE-2019-3775?
CVE-2019-3775 has a severity rating of 6.5, which is considered high.
How does CVE-2019-3775 affect Cloud Foundry UAA?
CVE-2019-3775 affects Cloud Foundry UAA versions prior to v70.0, allowing a user to update their own email address and impersonate a different user.
How can I mitigate CVE-2019-3775?
To mitigate CVE-2019-3775, it is recommended to upgrade to Cloud Foundry UAA version v70.0 or later.
Where can I find more information about CVE-2019-3775?
You can find more information about CVE-2019-3775 at the following link: [https://www.cloudfoundry.org/blog/cve-2019-3775]