CVE-2017-8031

Source
https://cve.org/CVERecord?id=CVE-2017-8031
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8031.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2017-8031
Aliases
Published
2017-11-27T10:29:00.767Z
Modified
2026-08-27T08:19:17.219712Z
Severity
  • 5.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.

References

Affected packages

Git / github.com/cloudfoundry-attic/cf-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry-attic/cf-release
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected
Database specific
Show details
{
    "source": "CPE_RANGE",
    "cpe": "cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*",
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "last_affected": "278"
        }
    ]
}

Affected versions

Other
-
list
log
scotty_09012012
v100
v102
v103
v104
v105
v109
v119
v132
v133
v134
v135
v136
v137
v140
v143
v156
v157
v161
v170
v183
v205
v245
v249
v253
v260
v262
v275
v276
v278
v99
works-for-us
rc145.*
rc145.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8031.json"

Git / github.com/cloudfoundry/uaa-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/uaa-release
Events
Database specific
Show details
{
    "source": [
        "CPE_RANGE",
        "CPE_STRING"
    ],
    "cpe": [
        "cpe:2.3:a:cloudfoundry:uaa-release:*:*:*:*:*:*:*:*",
        "cpe:2.3:a:cloudfoundry:uaa-release:52:*:*:*:*:*:*:*"
    ],
    "extracted_events": [
        {
            "introduced": "30"
        },
        {
            "fixed": "30.6"
        },
        {
            "introduced": "45"
        },
        {
            "fixed": "45.4"
        },
        {
            "introduced": "52"
        },
        {
            "last_affected": "52"
        }
    ]
}

Affected versions

Other
52
v30
v45
v52
v30.*
v30.1
v30.2
v30.3
v30.4
v30.5
v45.*
v45.3

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8031.json"