PT-2017-16249 · Cloud Foundry Foundation · Cf-Release+1
Published
2017-06-13
·
Updated
2022-06-03
·
CVE-2017-4991
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Foundation cf-release versions prior to v260
UAA release 2.x versions prior to v2.7.4.16
UAA release 3.6.x versions prior to v3.6.10
UAA release 3.9.x versions prior to v3.9.12
UAA release versions prior to v3.17.0
UAA bosh release (uaa-release) 13.x versions prior to v13.14
UAA bosh release (uaa-release) 24.x versions prior to v24.9
UAA bosh release (uaa-release) 30.x versions prior to 30.2
UAA bosh release (uaa-release) versions prior to v36
Description
An issue was discovered that allows privileged users in one zone to perform a password reset for users in a different zone.
Recommendations
For Cloud Foundry Foundation cf-release versions prior to v260, update to version v260 or later.
For UAA release 2.x versions prior to v2.7.4.16, update to version v2.7.4.16 or later.
For UAA release 3.6.x versions prior to v3.6.10, update to version v3.6.10 or later.
For UAA release 3.9.x versions prior to v3.9.12, update to version v3.9.12 or later.
For UAA release versions prior to v3.17.0, update to version v3.17.0 or later.
For UAA bosh release (uaa-release) 13.x versions prior to v13.14, update to version v13.14 or later.
For UAA bosh release (uaa-release) 24.x versions prior to v24.9, update to version v24.9 or later.
For UAA bosh release (uaa-release) 30.x versions prior to 30.2, update to version 30.2 or later.
For UAA bosh release (uaa-release) versions prior to v36, update to version v36 or later.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Uaa
Cf-Release