CVE-2017-8034
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
17/07/2017
Last modified:
20/04/2025
Description
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Impact
Base Score 3.x
6.60
Severity 3.x
MEDIUM
Base Score 2.0
6.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:* | 1.31.0 (including) | |
cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | 266 (including) | |
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:* | 0.158.0 (including) |
To consult the complete list of CPE names with products and versions, see this page