AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2019-3798

MEDIUM · CVSS 6 EPSS 1.36%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-04-17 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2019-3798
Severity
MEDIUM
CVSS
6
EPSS
1.36%

Original NVD Description

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the victim by creating a client with a name equal to the guid of their victim.