CVE-2017-8034

MEDIUM

Cloud Foundry <1.32.0-0.159.0-267 - Privilege Escalation

Title source: llm

Description

The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.

Scores

CVSS v3 6.6
EPSS 0.0047
EPSS Percentile 64.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-565
Status published
Products (4)
cloudfoundry/capi-release < 1.31.0
cloudfoundry/cf-release < 266
cloudfoundry/routing-release < 0.158.0
n/a/Cloud Foundry < Cloud Foundry
Published Jul 17, 2017
Tracked Since Feb 18, 2026