PT-2017-16229 · Cloud Foundry Foundation · Bosh Release
Published
2017-06-13
·
Updated
2019-10-03
·
CVE-2017-4961
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Foundation BOSH Release versions prior to 261.3
Cloud Foundry Foundation BOSH Release 260.x versions
Description
An issue allows an authenticated Director user to potentially escalate their privileges on the Director VM by providing a malicious checksum.
Recommendations
For Cloud Foundry Foundation BOSH Release versions prior to 261.3, update to version 261.3 or later.
For Cloud Foundry Foundation BOSH Release 260.x versions, update to version 261.3 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh Release