Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-8034

Опубликовано: 17 июл. 2017
Источник: nvd
CVSS3: 6.6
CVSS2: 6
EPSS Низкий

Описание

The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:*
Версия до 1.31.0 (включая)
cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*
Версия до 266 (включая)
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:*
Версия до 0.158.0 (включая)

EPSS

Процентиль: 64%
0.00472
Низкий

6.6 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-565

Связанные уязвимости

CVSS3: 6.6
github
больше 3 лет назад

The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.

EPSS

Процентиль: 64%
0.00472
Низкий

6.6 Medium

CVSS3

6 Medium

CVSS2

Дефекты

CWE-565