{"id":"CVE-2019-11279","details":"CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.","modified":"2026-07-08T15:54:31.490756Z","published":"2019-09-26T22:15:11.297Z","references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2019-11279"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/uaa-release","events":[{"introduced":"0"},{"fixed":"65f366b9bbe2711a7c518cc040b6e56d8b50a383"}],"database_specific":{"cpe":"cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"74.1.0"}],"source":"CPE_RANGE"}}],"versions":["v74.0.0","v73.7.0","v73.4.0","v73.3.0","v73.0.0","v72.0","v71.0","v70.0","v69.0","v68.0","v67.0","v66.0","v64.0","v63.0","v62.0","v61.0","v60","v55","v59","v58","v57","v56","v53","v31","v27","v26","v24","v25","v23","v22","v21","v20","v19","v18","v17","v16","v15","v14","v12.3","ci-upgrade","v12","v11","v10","v9","v8","v7","v6","v3","v2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11279.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}