First published: Tue Feb 26 2019(Updated: )
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Uaa Release | <70.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-3775 is a vulnerability in Cloud Foundry UAA that allows a user to impersonate a different user by changing their email address.
CVE-2019-3775 has a severity rating of 6.5, which is considered high.
CVE-2019-3775 affects Cloud Foundry UAA versions prior to v70.0, allowing a user to update their own email address and impersonate a different user.
To mitigate CVE-2019-3775, it is recommended to upgrade to Cloud Foundry UAA version v70.0 or later.
You can find more information about CVE-2019-3775 at the following link: [https://www.cloudfoundry.org/blog/cve-2019-3775]