VDB
CVE-2017-4973
CVE-2017-4973
PUBLISHED
CVSS 6.5 MEDIUM
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. A vulnerability has been identified with the groups endpoint in UAA allowing users to elevate their privileges.
EPSS 1.07% · 61.6th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
1.07%
61.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Cloud Foundry UAA | * |
| pivotal_software | cloud_foundry_cf | 0 |
| pivotal_software | cloud_foundry_uaa | 3.6.1, 2.7.4.7, 2.7.4.8 |
| Maven | org.cloudfoundry.identity:cloudfoundry-identity-server | 2.0.0, 3.7.0, 3.10.0 |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.4, 13.5, 13.6 |
Timeline
- Jun 13, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://www.cloudfoundry.org/cve-2017-4973/ url
- https://nvd.nist.gov/vuln/detail/CVE-2017-4973 advisory
- https://github.com/cloudfoundry/uaa/commit/0762cc768592abc4fb1c6afd9974ea6fb964f0f2 url
- https://github.com/cloudfoundry/uaa/commit/18cf22ba9177f1124f85f99651b474b48f12cd28 url
- https://github.com/cloudfoundry/uaa/commit/24bc5ade80560cedb9300940d2b398163ab0dc6 url
- https://github.com/cloudfoundry/uaa/commit/24c270ce725df890727b2bd7d8a4f338a3a58b7 url
- https://github.com/cloudfoundry/uaa/commit/3c456f0285e92713a0a9ce54c3e57d8636b9183c url
- https://github.com/cloudfoundry/uaa/commit/52acfabd11c3c77c2a3f5229b32f56de0e8d26ad url
- https://github.com/cloudfoundry/uaa/commit/5eb43757d5a3a2c9e7aae1ef3d0b9b7e2a38851e url
- https://github.com/cloudfoundry/uaa/commit/9d44cb0c7c25ccae95bfa1c2d59ce46200c643cb url
- https://github.com/cloudfoundry/uaa package
- https://www.cloudfoundry.org/cve-2017-4973 url