CVE-2017-8031
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.
Se ha descubierto un problema en Cloud Foundry Foundation cf-release (todas las versiones anteriores a v279) y UAA (versiones 30.x anteriores a la 30.6; versiones 45.x anteriores a la 45.4 y versiones 52.x anteriores a la 52.1). En algunos casos, UAA permite que un usuario autenticado para un cliente particular revoque tokens de cliente para otros usuarios en el mismo cliente. Esto solo ocurre si el cliente está usando tokens opacos o tokens JWT validados empleando el extremo check_token. Un actor malicioso podría provocar una denegación de servicio (DoS).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-21 CVE Reserved
- 2017-11-27 CVE Published
- 2023-10-07 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/101967 | Third Party Advisory | |
https://www.cloudfoundry.org/cve-2017-8031 | Issue Tracking |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudfoundry Search vendor "Cloudfoundry" | Cf-release Search vendor "Cloudfoundry" for product "Cf-release" | <= 278 Search vendor "Cloudfoundry" for product "Cf-release" and version " <= 278" | - |
Affected
| ||||||
Cloudfoundry Search vendor "Cloudfoundry" | Uaa-release Search vendor "Cloudfoundry" for product "Uaa-release" | >= 30 < 30.6 Search vendor "Cloudfoundry" for product "Uaa-release" and version " >= 30 < 30.6" | - |
Affected
| ||||||
Cloudfoundry Search vendor "Cloudfoundry" | Uaa-release Search vendor "Cloudfoundry" for product "Uaa-release" | >= 45 < 45.4 Search vendor "Cloudfoundry" for product "Uaa-release" and version " >= 45 < 45.4" | - |
Affected
| ||||||
Cloudfoundry Search vendor "Cloudfoundry" | Uaa-release Search vendor "Cloudfoundry" for product "Uaa-release" | 52 Search vendor "Cloudfoundry" for product "Uaa-release" and version "52" | - |
Affected
|