CVE-2017-4992

Source
https://nvd.nist.gov/vuln/detail/CVE-2017-4992
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4992.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-4992
Aliases
Published
2017-06-13T06:29:00Z
Modified
2024-09-03T01:55:40.714505Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior to v24.10, 30.x versions prior to 30.3, and other versions prior to v37. There is privilege escalation (arbitrary password reset) with user invitations.

References

Affected packages

Git / github.com/cloudfoundry/cf-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/cf-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Type
GIT
Repo
https://github.com/cloudfoundry/uaa
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Last affected
Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events

Affected versions

Other

-
ci-upgrade
lenient_hybrid_flow
list
log
scotty_09012012
travis-success-1475
travis-success-1478
travis-success-1497
v
v10
v100
v101
v102
v103
v104
v105
v106
v107
v108
v109
v11
v110
v111
v112
v113
v114
v115
v116
v117
v118
v119
v119-fixed
v12
v120
v121
v122
v123
v124
v125
v126
v127
v128
v129
v13
v130
v131
v132
v133
v134
v135
v136
v137
v138
v139
v14
v140
v141
v142
v143
v144
v145
v146
v147
v148
v149
v15
v150
v151
v152
v153
v154
v155
v156
v157
v158
v159
v16
v160
v161
v162
v163
v164
v165
v166
v168
v169
v17
v170
v171
v172
v173
v175
v176
v177
v178
v179
v18
v180
v182
v183
v186
v187
v188
v189
v19
v190
v191
v192
v193
v194
v195
v196
v197
v198
v199
v2
v20
v200
v201
v202
v203
v204
v205
v206
v207
v208
v209
v21
v210
v211
v212
v213
v214
v215
v217
v218
v219
v22
v220
v221
v222
v223
v224
v225
v226
v227
v228
v229
v23
v230
v231
v232
v233
v234
v235
v236
v237
v238
v239
v24
v240
v241
v242
v243
v244
v245
v246
v247
v248
v249
v25
v250
v251
v252
v253
v254
v255
v256
v257
v258
v259
v26
v260
v27
v3
v4
v5
v6
v68
v69
v7
v70
v71
v72
v73
v74
v75
v76
v77
v78
v79
v8
v80
v81
v82
v83
v84
v85
v86
v87
v88
v89
v9
v90
v91
v92
v93
v94
v95
v95-fixed
v96
v97
v98
v99
works-for-us

1.*

1.0.1
1.0.2
1.0.3
1.1
1.1.1
1.1.2
1.10
1.11
1.2.0
1.2.1
1.2.2
1.2.3
1.2.4
1.2.5
1.2.6
1.3.1
1.4.0
1.4.1
1.4.2
1.4.3
1.4.4
1.4.5
1.4.6
1.4.7
1.5.0
1.5.2
1.5.2.1
1.5.3
1.5.4
1.5.4.1
1.6.0
1.6.1
1.6.2
1.6.3
1.6.4
1.6.5
1.7.0
1.7.1
1.7.2
1.8.0
1.8.1
1.8.2
1.8.3
1.9.0
1.9.1

2.*

2.0.0
2.0.1
2.0.2
2.0.3
2.1.0
2.2.0
2.2.4
2.2.4.1
2.2.5
2.2.6
2.3.0
2.3.1
2.3.1.1
2.4.0
2.4.1
2.5.0
2.5.1
2.5.2
2.6.0
2.6.1
2.6.2
2.7.0
2.7.0.1
2.7.0.2
2.7.0.3
2.7.1
2.7.2
2.7.3

3.*

3.0.0
3.0.1
3.1.0
3.10.0
3.11.0
3.12.0
3.13.0
3.14.0
3.15.0
3.16.0
3.2.0
3.2.1
3.3.0
3.3.0.1
3.4.0
3.4.1
3.4.2
3.5.0
3.6.0
3.6.1
3.6.2
3.6.3
3.6.4
3.6.5
3.6.6
3.6.7
3.6.8
3.6.9
3.7.0
3.7.1
3.7.2
3.7.3
3.7.4
3.8.0
3.9.0
3.9.1
3.9.2
3.9.3

4.*

4.0.0
4.1.0
4.2.0

rc145.*

rc145.0

v11.*

v11.1
v11.2
v11.3

v12.*

v12.1
v12.2
v12.3

v13.*

v13.1
v13.2
v13.3
v13.4
v13.5

v24.*

v24.1
v24.2
v24.3
v24.4
v24.5
v24.6
v24.7
v24.8