PT-2017-18076 · Cloud Foundry Foundation · Cf-Release+1

Publicado

2017-11-27

·

Atualizado

2022-05-13

·

CVE-2017-8031

CVSS v3.1

5.3

Média

VetorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation cf-release versions prior to v279 UAA versions prior to 30.6 in the 30.x range UAA versions prior to 45.4 in the 45.x range UAA versions prior to 52.1 in the 52.x range
Description The issue allows an authenticated user for a particular client to revoke client tokens for other users on the same client, potentially causing denial of service. This occurs when the client is using opaque tokens or JWT tokens validated using the check token endpoint.
Recommendations For Cloud Foundry Foundation cf-release versions prior to v279, update to version v279 or later. For UAA 30.x versions prior to 30.6, update to version 30.6 or later. For UAA 45.x versions prior to 45.4, update to version 45.4 or later. For UAA 52.x versions prior to 52.1, update to version 52.1 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-8031
GHSA-J4P3-2M2H-CV5F

Produtos afetados

Uaa
Cf-Release