PT-2017-16251 · Cloud Foundry Foundation · Cf-Release+1

Publicado

2017-06-13

·

Atualizado

2021-08-06

·

CVE-2017-4994

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation cf-release versions prior to v263 UAA release 2.x versions prior to v2.7.4.18 UAA release 3.6.x versions prior to v3.6.12 UAA release 3.9.x versions prior to v3.9.14 UAA release versions prior to v4.3.0 UAA bosh release (uaa-release) 13.x versions prior to v13.16 UAA bosh release (uaa-release) 24.x versions prior to v24.11 UAA bosh release (uaa-release) 30.x versions prior to 30.4 UAA bosh release (uaa-release) versions prior to v40
Description There was an issue with forwarded http headers in UAA that could result in account corruption.
Recommendations For Cloud Foundry Foundation cf-release versions prior to v263, update to version v263 or later. For UAA release 2.x versions prior to v2.7.4.18, update to version v2.7.4.18 or later. For UAA release 3.6.x versions prior to v3.6.12, update to version v3.6.12 or later. For UAA release 3.9.x versions prior to v3.9.14, update to version v3.9.14 or later. For UAA release versions prior to v4.3.0, update to version v4.3.0 or later. For UAA bosh release (uaa-release) 13.x versions prior to v13.16, update to version v13.16 or later. For UAA bosh release (uaa-release) 24.x versions prior to v24.11, update to version v24.11 or later. For UAA bosh release (uaa-release) 30.x versions prior to 30.4, update to version 30.4 or later. For UAA bosh release (uaa-release) versions prior to v40, update to version v40 or later.

Correção

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-4994

Produtos afetados

Uaa
Cf-Release