CVE-2017-8034
MEDIUMCloud Foundry <1.32.0-0.159.0-267 - Privilege Escalation
Title source: llmDescription
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Scores
CVSS v3
6.6
EPSS
0.0047
EPSS Percentile
64.4%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-565
Status
published
Products (4)
cloudfoundry/capi-release
< 1.31.0
cloudfoundry/cf-release
< 266
cloudfoundry/routing-release
< 0.158.0
n/a/Cloud Foundry
< Cloud Foundry
Published
Jul 17, 2017
Tracked Since
Feb 18, 2026