CVE-2017-8034
17.07.2017, 14:29
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | capi-release | 𝑥 ≤ 1.31.0 |
cloudfoundry | cf-release | 𝑥 ≤ 266 |
cloudfoundry | routing-release | 𝑥 ≤ 0.158.0 |
𝑥
= Vulnerable software versions