VDB
CVE-2017-4991
CVE-2017-4991
PUBLISHED
CVSS 7.199999809265137 HIGH
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions prior to v24.9, 30.x versions prior to 30.2, and other versions prior to v36. Privileged users in one zone are allowed to perform a password reset for users in a different zone.
EPSS 0.94% · 57.5th percentile
Risk Scores
CVSS 3.1
7.199999809265137
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.94%
57.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | Cloud Foundry UAA | Cloud Foundry UAA |
| Maven | org.cloudfoundry.identity:cloudfoundry-identity-server | 2.0.0, 3.0.0, 3.7.0 |
| pivotal_software | cloud_foundry_uaa | 3.6.2, 2.7.4.8, 2.7.4.9 |
| cloudfoundry | cloud_foundry_uaa_bosh | 0, 13.3, 13.4 |
| cloudfoundry | cf-release | 0 |
Timeline
- Jun 13, 2017 CVE Published
- Apr 14, 2021 EPSS Score
- Jun 23, 2021 EPSS Score
- Aug 24, 2021 EPSS Score
- Oct 26, 2021 EPSS Score
- Dec 27, 2021 EPSS Score
- Feb 28, 2022 EPSS Score
- May 2, 2022 EPSS Score
- Jul 3, 2022 EPSS Score
- Sep 5, 2022 EPSS Score
- Nov 7, 2022 EPSS Score
- Jan 8, 2023 EPSS Score
References
- https://www.cloudfoundry.org/cve-2017-4991/ url
- https://nvd.nist.gov/vuln/detail/CVE-2017-4991 advisory
- https://github.com/cloudfoundry/uaa/commit/2ca35f1723e039aa7d2318134b05d02e40072a18 url
- https://github.com/cloudfoundry/uaa/commit/ba23bcf109704ab2eae519b705d7b2a75e023553 url
- https://github.com/cloudfoundry/uaa/commit/bbf6751bc0d87c4a3aaf21b54e26ce328ab998b3 url
- https://github.com/cloudfoundry/uaa/commit/eb3f86054489039e11eabd54a8ec9a46c22abfc8 url
- https://github.com/cloudfoundry/uaa package
- https://www.cloudfoundry.org/cve-2017-4991 url