CVE-2017-8031
MEDIUM
5,3
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: low
User Interaction: none
Scope: unchanged
Confidentiality: none
Integrity: none
Availability: high
LOW
3,5
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: single
Confidentiality: none
Integrity: none
Availability: partial
Description
AI Translation Available
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0042
Percentile
0,6th
Updated
EPSS Score Trend (Last 90 Days)
Application
Uaa-Release by Cloudfoundry
CPE Identifier
View Detailed Analysis
cpe:2.3:a:cloudfoundry:uaa-release:52:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Uaa-Release by Cloudfoundry
Version Range Affected
From
30
(inclusive)
To
30.6
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:cloudfoundry:uaa-release:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Cf-Release by Cloudfoundry
Version Range Affected
To
278
(inclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Uaa-Release by Cloudfoundry
Version Range Affected
From
45
(inclusive)
To
45.4
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:cloudfoundry:uaa-release:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cloudfoundry.org/cve-2017-8031/
http://www.securityfocus.com/bid/101967
https://www.cloudfoundry.org/cve-2017-8031/
http://www.securityfocus.com/bid/101967