CVE-2016-0732: High severity Cloudfoundry Cf-release vulnerability
Published Sep 7, 2017
·Updated
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
Affected Software
51 affected components
Cloudfoundry Cf-release>=208<=229
Cloudfoundry User Account And Authentication=2.0.0
Cloudfoundry User Account And Authentication=2.0.1
Cloudfoundry User Account And Authentication=2.0.2
Cloudfoundry User Account And Authentication=2.0.3
Cloudfoundry User Account And Authentication=2.1.0
Cloudfoundry User Account And Authentication=2.2.0
Cloudfoundry User Account And Authentication=2.2.1
Cloudfoundry User Account And Authentication=2.2.2
Cloudfoundry User Account And Authentication=2.2.3
Cloudfoundry User Account And Authentication=2.2.4
Cloudfoundry User Account And Authentication=2.2.4.1
Cloudfoundry User Account And Authentication=2.2.5
Cloudfoundry User Account And Authentication=2.2.5.2
Cloudfoundry User Account And Authentication=2.2.5.3
Cloudfoundry User Account And Authentication=2.2.6
Cloudfoundry User Account And Authentication=2.3.0
Cloudfoundry User Account And Authentication=2.3.1
Cloudfoundry User Account And Authentication=2.3.1.1
Cloudfoundry User Account And Authentication=2.4.0
Cloudfoundry User Account And Authentication=2.4.1
Cloudfoundry User Account And Authentication=2.5.0
Cloudfoundry User Account And Authentication=2.5.1
Cloudfoundry User Account And Authentication=2.5.2
Cloudfoundry User Account And Authentication=2.6.0
Cloudfoundry User Account And Authentication=2.6.1
Cloudfoundry User Account And Authentication=2.6.2
Cloudfoundry User Account And Authentication=2.7.0
Cloudfoundry User Account And Authentication=2.7.0.1
Cloudfoundry User Account And Authentication=2.7.0.2
Cloudfoundry User Account And Authentication=2.7.0.3
Cloudfoundry User Account And Authentication=2.7.1
Cloudfoundry User Account And Authentication=2.7.2
Cloudfoundry User Account And Authentication=2.7.3
Cloudfoundry Uaa-release=2
Cloudfoundry Uaa-release=3
Cloudfoundry Uaa-release=4
Pivotal Elastic Runtime=1.6.0
Pivotal Elastic Runtime=1.6.1
Pivotal Elastic Runtime=1.6.2
Pivotal Elastic Runtime=1.6.3
Pivotal Elastic Runtime=1.6.4
Pivotal Elastic Runtime=1.6.5
Pivotal Elastic Runtime=1.6.6
Pivotal Elastic Runtime=1.6.7
Pivotal Elastic Runtime=1.6.8
Pivotal Elastic Runtime=1.6.9
Pivotal Elastic Runtime=1.6.10
Pivotal Elastic Runtime=1.6.11
Pivotal Elastic Runtime=1.6.12
Pivotal Elastic Runtime=1.6.13
Event History
Sep 7, 2017
CVE Published
via MITRE·01:00 PM
Data Sourced
via MITRE·01:00 PM
Description
Frequently Asked Questions
1
What is the main impact of CVE-2016-0732?
The main impact of CVE-2016-0732 is the potential for privilege escalation between identity zones in Pivotal Cloud Foundry.