CVE-2017-4964

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
06/04/2017
Last modified:
20/04/2025

Description

Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a "CPI code injection vulnerability."

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:bosh_azure_cpi:22:*:*:*:*:*:*:*