CVE-2017-4973

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. A vulnerability has been identified with the groups endpoint in UAA allowing users to elevate their privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
dellCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 53%
VendorProductVersion
cloudfoundrycloud_foundry_uaa_bosh
𝑥
≤ 30
cloudfoundrycloud_foundry_uaa_bosh
13.1
cloudfoundrycloud_foundry_uaa_bosh
13.2
cloudfoundrycloud_foundry_uaa_bosh
13.3
cloudfoundrycloud_foundry_uaa_bosh
13.4
cloudfoundrycloud_foundry_uaa_bosh
13.5
cloudfoundrycloud_foundry_uaa_bosh
13.6
cloudfoundrycloud_foundry_uaa_bosh
13.7
cloudfoundrycloud_foundry_uaa_bosh
13.8
cloudfoundrycloud_foundry_uaa_bosh
13.9
cloudfoundrycloud_foundry_uaa_bosh
13.10
cloudfoundrycloud_foundry_uaa_bosh
13.11
cloudfoundrycloud_foundry_uaa_bosh
24.1
cloudfoundrycloud_foundry_uaa_bosh
24.2
cloudfoundrycloud_foundry_uaa_bosh
24.3
cloudfoundrycloud_foundry_uaa_bosh
24.4
cloudfoundrycloud_foundry_uaa_bosh
24.5
cloudfoundrycloud_foundry_uaa_bosh
24.6
cloudfoundrycloud_foundry_uaa_bosh
30.1
cloudfoundrycloud_foundry_uaa_bosh
30.2
cloudfoundrycloud_foundry_uaa_bosh
30.3
pivotal_softwarecloud_foundry_cf
𝑥
≤ 256
pivotal_softwarecloud_foundry_uaa
2.2.5.4
pivotal_softwarecloud_foundry_uaa
2.7.1
pivotal_softwarecloud_foundry_uaa
2.7.2
pivotal_softwarecloud_foundry_uaa
2.7.3
pivotal_softwarecloud_foundry_uaa
2.7.4
pivotal_softwarecloud_foundry_uaa
2.7.4.1
pivotal_softwarecloud_foundry_uaa
2.7.4.2
pivotal_softwarecloud_foundry_uaa
2.7.4.3
pivotal_softwarecloud_foundry_uaa
2.7.4.4
pivotal_softwarecloud_foundry_uaa
2.7.4.5
pivotal_softwarecloud_foundry_uaa
2.7.4.6
pivotal_softwarecloud_foundry_uaa
2.7.4.7
pivotal_softwarecloud_foundry_uaa
2.7.4.8
pivotal_softwarecloud_foundry_uaa
2.7.4.9
pivotal_softwarecloud_foundry_uaa
2.7.4.11
pivotal_softwarecloud_foundry_uaa
2.7.4.12
pivotal_softwarecloud_foundry_uaa
2.7.4.13
pivotal_softwarecloud_foundry_uaa
3.6.1
pivotal_softwarecloud_foundry_uaa
3.6.2
pivotal_softwarecloud_foundry_uaa
3.6.3
pivotal_softwarecloud_foundry_uaa
3.6.4
pivotal_softwarecloud_foundry_uaa
3.6.5
pivotal_softwarecloud_foundry_uaa
3.6.6
pivotal_softwarecloud_foundry_uaa
3.6.7
pivotal_softwarecloud_foundry_uaa
3.9.1
pivotal_softwarecloud_foundry_uaa
3.9.2
pivotal_softwarecloud_foundry_uaa
3.9.3
pivotal_softwarecloud_foundry_uaa
3.9.4
pivotal_softwarecloud_foundry_uaa
3.9.5
pivotal_softwarecloud_foundry_uaa
3.9.6
pivotal_softwarecloud_foundry_uaa
3.9.7
pivotal_softwarecloud_foundry_uaa
3.9.8
pivotal_softwarecloud_foundry_uaa
3.9.9
pivotal_softwarecloud_foundry_uaa
3.9.12
pivotal_softwarecloud_foundry_uaa
3.9.13
𝑥
= Vulnerable software versions