{"id":"CVE-2019-11270","details":"Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.","modified":"2026-07-08T05:52:47.294591380Z","published":"2019-08-05T17:15:10.820Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"pivotal_software:application_service","cpes":["cpe:2.3:a:pivotal_software:application_service:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0"},{"fixed":"2.3.15"},{"introduced":"2.4.0"},{"fixed":"2.4.11"},{"introduced":"2.5.0"},{"fixed":"2.5.7"},{"introduced":"2.6.0"},{"fixed":"2.6.2"}]},{"vendor_product":"pivotal_software:operations_manager","cpes":["cpe:2.3:a:pivotal_software:operations_manager:*:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"2.3.0"},{"fixed":"2.3.22"},{"introduced":"2.4.0"},{"fixed":"2.4.16"},{"introduced":"2.5.0"},{"fixed":"2.5.10"},{"introduced":"2.6.0"},{"fixed":"2.6.4"}],"source":"CPE_RANGE"}]},"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2019-11270"},{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2019-11270"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa-release","events":[{"introduced":"0"},{"fixed":"9040931f8c2a2754a5b585ad8900e27612245bda"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"73.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:*"}}],"versions":["v73.3.0","v73.0.0","v72.0","v71.0","v70.0","v69.0","v68.0","v67.0","v66.0","v64.0","v63.0","v62.0","v61.0","v60","v55","v59","v58","v57","v56","v53","v31","v27","v26","v24","v25","v23","v22","v21","v20","v19","v18","v17","v16","v15","v14","v12.3","ci-upgrade","v12","v11","v10","v9","v8","v7","v6","v3","v2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11270.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N"}]}