An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an "Unauthenticated JWT signing algorithm in multiple components" issue.
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "1.6.0"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "1.6.5"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.1"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.2"
},
{
"introduced": "0"
},
{
"last_affected": "1.8.3"
},
{
"introduced": "0"
},
{
"last_affected": "1.9.0"
}
]
}[
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.36"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.37"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.40"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.41"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.42"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.43"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.44"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.45"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.46"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.47"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.48"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.49"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.50"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.51"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.52"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.53"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.54"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.55"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.56"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.57"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.58"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.6.59"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.3"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.22"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.23"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.24"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.25"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.26"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.27"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.28"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.29"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.30"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.31"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.32"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.33"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.34"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.35"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.36"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.37"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.38"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.39"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.7.40"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.4"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.5"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.6"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.7"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.8"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.9"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.10"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.11"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.12"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.13"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.14"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.15"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.16"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.17"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.18"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.19"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.20"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.21"
}
]
},
{
"events": [
{
"introduced": "0"
},
{
"last_affected": "1.8.22"
}
]
}
]
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-2773.json"