PT-2017-16229 · Cloud Foundry Foundation · Bosh Release

Published

2017-06-13

·

Updated

2019-10-03

·

CVE-2017-4961

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation BOSH Release versions prior to 261.3 Cloud Foundry Foundation BOSH Release 260.x versions
Description An issue allows an authenticated Director user to potentially escalate their privileges on the Director VM by providing a malicious checksum.
Recommendations For Cloud Foundry Foundation BOSH Release versions prior to 261.3, update to version 261.3 or later. For Cloud Foundry Foundation BOSH Release 260.x versions, update to version 261.3 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-4961

Affected Products

Bosh Release