CVE-2016-8218

See a problem?
Source
https://nvd.nist.gov/vuln/detail/CVE-2016-8218
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-8218.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2016-8218
Published
2017-06-13T06:29:00Z
Modified
2024-09-03T01:28:13.417586Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

References

Affected packages

Git / github.com/cloudfoundry/cf-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/cf-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Type
GIT
Repo
https://github.com/cloudfoundry/routing-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

Other

-
list
log
scotty_09012012
v
v100
v101
v102
v103
v104
v105
v106
v107
v108
v109
v110
v111
v112
v113
v114
v115
v116
v117
v118
v119
v119-fixed
v120
v121
v122
v123
v124
v125
v126
v127
v128
v129
v130
v131
v132
v133
v134
v135
v136
v137
v138
v139
v140
v141
v142
v143
v144
v145
v146
v147
v148
v149
v150
v151
v152
v153
v154
v155
v156
v157
v158
v159
v160
v161
v162
v163
v164
v165
v166
v168
v169
v170
v171
v172
v173
v175
v176
v177
v178
v179
v180
v182
v183
v186
v187
v188
v189
v190
v191
v192
v193
v194
v195
v196
v197
v198
v199
v200
v201
v202
v203
v204
v205
v206
v207
v208
v209
v210
v211
v212
v213
v214
v215
v217
v218
v219
v68
v69
v70
v71
v72
v73
v74
v75
v76
v77
v78
v79
v80
v81
v82
v83
v84
v85
v86
v87
v88
v89
v90
v91
v92
v93
v94
v95
v95-fixed
v96
v97
v98
v99
works-for-us

0.*

0.118.0
0.121.0
0.123.0
0.126.0
0.133.0
0.134.0
0.135.0
0.136.0
0.137.0
0.138.0
0.139.0
0.140.0
0.141.0
0.62.0
0.66.0
0.69.0
0.99.0

rc145.*

rc145.0