Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2017-4994


An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior to v24.11, 30.x versions prior to 30.4, and other versions prior to v40. There was an issue with forwarded http headers in UAA that could result in account corruption.


Published

2017-06-13T06:29:00.800

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cloudfoundry cloud_foundry_uaa_bosh ≤ 39 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.1 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.2 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.3 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.4 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.5 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.6 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.7 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.8 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.9 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.10 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.11 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.12 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.13 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.14 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 13.15 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.1 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.2 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.3 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.4 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.5 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.6 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.7 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.8 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.9 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 24.10 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 30 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 30.1 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 30.2 Yes
Application cloudfoundry cloud_foundry_uaa_bosh 30.3 Yes
Application pivotal_software cloud_foundry_cf ≤ 262 Yes
Application pivotal_software cloud_foundry_uaa ≤ 4.2.0 Yes
Application pivotal_software cloud_foundry_uaa 2.2.5.4 Yes
Application pivotal_software cloud_foundry_uaa 2.7.1 Yes
Application pivotal_software cloud_foundry_uaa 2.7.2 Yes
Application pivotal_software cloud_foundry_uaa 2.7.3 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.1 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.2 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.3 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.4 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.5 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.6 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.7 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.8 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.9 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.11 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.12 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.13 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.14 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.15 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.16 Yes
Application pivotal_software cloud_foundry_uaa 2.7.4.17 Yes
Application pivotal_software cloud_foundry_uaa 3.6.1 Yes
Application pivotal_software cloud_foundry_uaa 3.6.2 Yes
Application pivotal_software cloud_foundry_uaa 3.6.3 Yes
Application pivotal_software cloud_foundry_uaa 3.6.4 Yes
Application pivotal_software cloud_foundry_uaa 3.6.5 Yes
Application pivotal_software cloud_foundry_uaa 3.6.6 Yes
Application pivotal_software cloud_foundry_uaa 3.6.7 Yes
Application pivotal_software cloud_foundry_uaa 3.6.8 Yes
Application pivotal_software cloud_foundry_uaa 3.6.9 Yes
Application pivotal_software cloud_foundry_uaa 3.6.10 Yes
Application pivotal_software cloud_foundry_uaa 3.6.11 Yes
Application pivotal_software cloud_foundry_uaa 3.9.1 Yes
Application pivotal_software cloud_foundry_uaa 3.9.2 Yes
Application pivotal_software cloud_foundry_uaa 3.9.3 Yes
Application pivotal_software cloud_foundry_uaa 3.9.4 Yes
Application pivotal_software cloud_foundry_uaa 3.9.5 Yes
Application pivotal_software cloud_foundry_uaa 3.9.6 Yes
Application pivotal_software cloud_foundry_uaa 3.9.7 Yes
Application pivotal_software cloud_foundry_uaa 3.9.8 Yes
Application pivotal_software cloud_foundry_uaa 3.9.9 Yes
Application pivotal_software cloud_foundry_uaa 3.9.10 Yes
Application pivotal_software cloud_foundry_uaa 3.9.11 Yes
Application pivotal_software cloud_foundry_uaa 3.9.12 Yes
Application pivotal_software cloud_foundry_uaa 3.9.13 Yes

References