PT-2017-9537 · Cloud Foundry Foundation · Cf-Release+1

Published

2017-06-13

·

Updated

2017-11-08

·

CVE-2016-8218

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation routing-release versions prior to 0.142.0 Cloud Foundry Foundation cf-release versions 203 through 231
Description An issue exists due to incomplete validation logic in JSON Web Token (JWT) libraries, allowing unprivileged attackers to impersonate other users to the routing API.
Recommendations For routing-release versions prior to 0.142.0, update to version 0.142.0 or later. For cf-release versions 203 through 231, update to a version after 231.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2016-8218

Affected Products

Cf-Release
Routing-Release