Vulnerabilities > Cloudfoundry > UAA Release > 68.0

DATE CVE VULNERABILITY TITLE RISK
2019-09-26 CVE-2019-11279 Unspecified vulnerability in Cloudfoundry UAA Release
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes.
network
low complexity
cloudfoundry
8.8
2019-04-25 CVE-2019-3788 Open Redirect vulnerability in Cloudfoundry UAA Release
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri.
network
low complexity
cloudfoundry CWE-601
6.1
2019-03-07 CVE-2019-3775 Improper Authentication vulnerability in Cloudfoundry UAA Release
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address.
network
low complexity
cloudfoundry CWE-287
6.5