8.8
CVSSv3

CVE-2019-3787

Published: 19/06/2019 Updated: 10/02/2020
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Cloud Foundry UAA, versions before 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially fraudulent address. This would allow the malicious user to gain complete control of the user's account.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software cloud foundry uaa-release