PT-2017-15529 · Pivotal · Pcf Elastic Runtime

Publicado

2017-06-13

·

Atualizado

2017-07-03

·

CVE-2017-2773

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Pivotal PCF Elastic Runtime versions prior to 1.6.60 Pivotal PCF Elastic Runtime versions prior to 1.7.41 Pivotal PCF Elastic Runtime versions prior to 1.8.23 Pivotal PCF Elastic Runtime versions prior to 1.9.1
Description The issue is related to incomplete validation logic in JSON Web Token (JWT) libraries, which can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime.
Recommendations For versions prior to 1.6.60, update to version 1.6.60 or later. For versions prior to 1.7.41, update to version 1.7.41 or later. For versions prior to 1.8.23, update to version 1.8.23 or later. For versions prior to 1.9.1, update to version 1.9.1 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-2773

Produtos afetados

Pcf Elastic Runtime