Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2016-8218

Опубликовано: 13 июн. 2017
Источник: nvd
CVSS3: 9.8
CVSS2: 7.5
EPSS Низкий

Описание

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*
Версия до 203 (включая)
cpe:2.3:a:cloudfoundry:cf-release:204:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:205:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:206:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:207:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:208:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:209:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:210:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:211:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:212:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:213:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:214:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:215:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:217:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:218:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:219:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:220:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:221:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:222:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:223:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:224:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:225:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:226:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:227:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:228:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:229:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:230:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-release:231:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:*
Версия до 0.141.0 (включая)

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 9.8
github
больше 3 лет назад

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

EPSS

Процентиль: 69%
0.00585
Низкий

9.8 Critical

CVSS3

7.5 High

CVSS2

Дефекты

CWE-20