PT-2017-16236 · Cloud Foundry Foundation · Cf-Release+1

Published

2017-06-13

·

Updated

2022-05-13

·

CVE-2017-4973

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation cf-release versions prior to v257 UAA release 2.x versions prior to v2.7.4.14 UAA release 3.6.x versions prior to v3.6.8 UAA release 3.9.x versions prior to v3.9.10 UAA release versions prior to v3.15.0 UAA bosh release (uaa-release) 13.x versions prior to v13.12 UAA bosh release (uaa-release) 24.x versions prior to v24.7 UAA bosh release (uaa-release) versions prior to v30
Description A vulnerability has been identified with the groups endpoint in UAA, allowing users to elevate their privileges.
Recommendations For Cloud Foundry Foundation cf-release versions prior to v257, update to version v257 or later. For UAA release 2.x versions prior to v2.7.4.14, update to version v2.7.4.14 or later. For UAA release 3.6.x versions prior to v3.6.8, update to version v3.6.8 or later. For UAA release 3.9.x versions prior to v3.9.10, update to version v3.9.10 or later. For UAA release versions prior to v3.15.0, update to version v3.15.0 or later. For UAA bosh release (uaa-release) 13.x versions prior to v13.12, update to version v13.12 or later. For UAA bosh release (uaa-release) 24.x versions prior to v24.7, update to version v24.7 or later. For UAA bosh release (uaa-release) versions prior to v30, update to version v30 or later.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-4973
GHSA-PGJC-GC7G-P2C6

Affected Products

Uaa
Cf-Release