PT-2017-18085 · Pivotal · Single Sign-On For Pivotal Cloud Foundry

Publicado

2017-09-09

·

Atualizado

2021-08-12

·

CVE-2017-8040

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Single Sign-On for Pivotal Cloud Foundry (PCF) versions 1.3.x prior to 1.3.4 Single Sign-On for Pivotal Cloud Foundry (PCF) versions 1.4.x prior to 1.4.3
Description An XXE (XML External Entity) attack was discovered in the Single Sign-On service dashboard, allowing privileged users to upload malformed XML. This can lead to exposure of data on the Single Sign-On service broker file system.
Recommendations For versions 1.3.x prior to 1.3.4, update to version 1.3.4 or later. For versions 1.4.x prior to 1.4.3, update to version 1.4.3 or later.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-8040

Produtos afetados

Single Sign-On For Pivotal Cloud Foundry