Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-4961

Опубликовано: 13 июн. 2017
Источник: nvd
CVSS3: 8.8
CVSS2: 6.5
EPSS Низкий

Описание

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*

EPSS

Процентиль: 42%
0.002
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-354

Связанные уязвимости

CVSS3: 8.8
github
больше 3 лет назад

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."

EPSS

Процентиль: 42%
0.002
Низкий

8.8 High

CVSS3

6.5 Medium

CVSS2

Дефекты

CWE-354