6.6
CVSSv3

CVE-2017-8032

Published: 10/07/2017 Updated: 06/08/2021
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 6.6 | Impact Score: 5.9 | Exploitability Score: 0.7
VMScore: 534
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to v24.12. 30.x versions before 30.5, and other versions prior to v41, zone administrators are allowed to escalate their privileges when mapping permissions for an external provider.

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal software cloud foundry uaa 2.2.5.4

pivotal software cloud foundry uaa 2.7.1

pivotal software cloud foundry uaa 2.7.2

pivotal software cloud foundry uaa 2.7.3

pivotal software cloud foundry uaa 2.7.4.14

pivotal software cloud foundry uaa 2.7.4.15

pivotal software cloud foundry uaa 2.7.4.16

pivotal software cloud foundry uaa 3.6.1

pivotal software cloud foundry uaa 3.9.3

pivotal software cloud foundry uaa 3.9.4

pivotal software cloud foundry uaa 3.9.5

pivotal software cloud foundry uaa 3.9.6

pivotal software cloud foundry uaa 2.7.4

pivotal software cloud foundry uaa 2.7.4.2

pivotal software cloud foundry uaa 2.7.4.4

pivotal software cloud foundry uaa 2.7.4.9

pivotal software cloud foundry uaa 2.7.4.12

pivotal software cloud foundry uaa 3.6.3

pivotal software cloud foundry uaa 3.6.5

pivotal software cloud foundry uaa 3.6.12

pivotal software cloud foundry uaa 3.9.2

pivotal software cloud foundry uaa 3.9.7

pivotal software cloud foundry uaa 3.9.9

pivotal software cloud foundry uaa 2.7.4.5

pivotal software cloud foundry uaa 2.7.4.6

pivotal software cloud foundry uaa 2.7.4.7

pivotal software cloud foundry uaa 2.7.4.8

pivotal software cloud foundry uaa 3.6.6

pivotal software cloud foundry uaa 3.6.7

pivotal software cloud foundry uaa 3.6.8

pivotal software cloud foundry uaa 3.6.9

pivotal software cloud foundry uaa 3.6.10

pivotal software cloud foundry uaa 3.9.11

pivotal software cloud foundry uaa 3.9.12

pivotal software cloud foundry uaa 3.9.13

pivotal software cloud foundry uaa 3.9.14

pivotal software cloud foundry uaa 2.7.4.1

pivotal software cloud foundry uaa 2.7.4.3

pivotal software cloud foundry uaa 2.7.4.11

pivotal software cloud foundry uaa 2.7.4.13

pivotal software cloud foundry uaa 3.6.2

pivotal software cloud foundry uaa 3.6.4

pivotal software cloud foundry uaa 3.6.11

pivotal software cloud foundry uaa 3.9.1

pivotal software cloud foundry uaa 3.9.8

pivotal software cloud foundry uaa 3.9.10

cloudfoundry cloud foundry uaa bosh 13.5

cloudfoundry cloud foundry uaa bosh 13.6

cloudfoundry cloud foundry uaa bosh 13.7

cloudfoundry cloud foundry uaa bosh 13.8

cloudfoundry cloud foundry uaa bosh 24.5

cloudfoundry cloud foundry uaa bosh 24.6

cloudfoundry cloud foundry uaa bosh 24.7

cloudfoundry cloud foundry uaa bosh 24.8

cloudfoundry cloud foundry uaa bosh 13.1

cloudfoundry cloud foundry uaa bosh 13.3

cloudfoundry cloud foundry uaa bosh 13.10

cloudfoundry cloud foundry uaa bosh 13.12

cloudfoundry cloud foundry uaa bosh 24

cloudfoundry cloud foundry uaa bosh 24.2

cloudfoundry cloud foundry uaa bosh 24.4

cloudfoundry cloud foundry uaa bosh 24.9

cloudfoundry cloud foundry uaa bosh 24.11

cloudfoundry cloud foundry uaa bosh 13.13

cloudfoundry cloud foundry uaa bosh 13.14

cloudfoundry cloud foundry uaa bosh 13.15

cloudfoundry cloud foundry uaa bosh 13.16

cloudfoundry cloud foundry uaa bosh 30.1

cloudfoundry cloud foundry uaa bosh 30.2

cloudfoundry cloud foundry uaa bosh 30.3

cloudfoundry cloud foundry uaa bosh 30.4

cloudfoundry cloud foundry uaa bosh 13.2

cloudfoundry cloud foundry uaa bosh 13.4

cloudfoundry cloud foundry uaa bosh 13.9

cloudfoundry cloud foundry uaa bosh 13.11

cloudfoundry cloud foundry uaa bosh 24.1

cloudfoundry cloud foundry uaa bosh 24.3

cloudfoundry cloud foundry uaa bosh 24.10

cloudfoundry cloud foundry uaa bosh 30

cloudfoundry cloud foundry uaa bosh

pivotal software cloud foundry cf

Recent Articles

Cloud Foundry had a privilege escalation bug
The Register • Richard Chirgwin • 11 Jul 2017

Mitigate if you must, patch if you can

Open source devops platform Cloud Foundry has disclosed a potentially nasty bug in its User Account and Authentication server software. UUA is the Cloud Foundry ID management service, using OAuth2 to issue tokens for client applications that act on behalf of users. CVE-2017-8032 was patched in an update last week, and the detailed advisory landed June 12 here. The short version: “Zone administrators are allowed to escalate their privileges when mapping permissions for an external provider.” ...