First published: Tue Jun 13 2017(Updated: )
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.60, 1.7.x versions prior to 1.7.41, 1.8.x versions prior to 1.8.23, and 1.9.x versions prior to 1.9.1. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users in multiple components included in PCF Elastic Runtime, aka an "Unauthenticated JWT signing algorithm in multiple components" issue.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Cloud Foundry Elastic Runtime | =1.6.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.16 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.21 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.22 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.23 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.24 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.25 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.26 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.27 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.28 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.29 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.30 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.31 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.32 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.33 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.34 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.35 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.36 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.37 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.38 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.39 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.40 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.41 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.42 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.43 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.44 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.45 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.46 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.47 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.48 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.49 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.50 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.51 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.52 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.53 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.54 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.55 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.56 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.57 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.58 | |
Pivotal Cloud Foundry Elastic Runtime | =1.6.59 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.16 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.21 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.22 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.23 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.24 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.25 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.26 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.27 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.28 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.29 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.30 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.31 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.32 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.33 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.34 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.35 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.36 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.37 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.38 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.39 | |
Pivotal Cloud Foundry Elastic Runtime | =1.7.40 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.16 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.21 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.22 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE-2017-2773 vulnerability is categorized as high severity due to its potential for attacker impersonation.
To fix CVE-2017-2773, upgrade Pivotal PCF Elastic Runtime to versions 1.6.60 or later, 1.7.41 or later, 1.8.23 or later, or 1.9.1 or later.
CVE-2017-2773 affects Pivotal PCF Elastic Runtime versions 1.6.x below 1.6.60, 1.7.x below 1.7.41, 1.8.x below 1.8.23, and 1.9.x below 1.9.1.
CVE-2017-2773 is an authentication-related vulnerability due to incomplete validation logic in JSON Web Token libraries.
CVE-2017-2773 can be exploited by unprivileged attackers to impersonate other users.