Show filters
1 Total Results
Displaying 1-1 of 1
Sort by:
Attacker Value
Unknown
Privilege Escalation via Scope Manipulation in UAA
Disclosure Date: September 26, 2019 (last updated November 27, 2024)
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.
0