PT-2017-16228 · Cloud Foundry Foundation · Cloud Foundry+1

Published

2017-03-10

·

Updated

2022-05-13

·

CVE-2017-4960

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry versions v247 through v252 UAA stand-alone versions v3.9.0 through v3.11.0 UAA Bosh Release versions v21 through v26
Description An issue was discovered that could subject the UAA OAuth clients to a denial of service attack. This issue has the potential to cause service disruption.
Recommendations For Cloud Foundry versions v247 through v252, update to a version outside of this range to resolve the issue. For UAA stand-alone versions v3.9.0 through v3.11.0, update to a version outside of this range to resolve the issue. For UAA Bosh Release versions v21 through v26, update to a version outside of this range to resolve the issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-4960
GHSA-HXGW-7539-PV7R

Affected Products

Cloud Foundry
Uaa