First published: Tue Jun 13 2017(Updated: )
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and potential escalation of privileges.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Cloud Foundry Elastic Runtime | =1.8.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.6 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.7 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.8 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.9 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.10 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.11 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.12 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.13 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.14 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.15 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.16 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.17 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.18 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.19 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.20 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.21 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.22 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.23 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.24 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.25 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.26 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.27 | |
Pivotal Cloud Foundry Elastic Runtime | =1.8.28 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.0 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.1 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.2 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.3 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.4 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.5 | |
Pivotal Cloud Foundry Elastic Runtime | =1.9.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-4959 has been assigned a medium severity rating due to its potential to allow unauthorized user account takeover.
To fix CVE-2017-4959, upgrade Pivotal Cloud Foundry Elastic Runtime to versions 1.8.29 or 1.9.7 and above.
CVE-2017-4959 affects Pivotal Cloud Foundry Elastic Runtime versions 1.8.x prior to 1.8.29 and 1.9.x prior to 1.9.7.
CVE-2017-4959 is a user account takeover vulnerability that can be exploited by an authorized user.
There are no known workarounds for CVE-2017-4959; upgrading to the patched versions is the recommended approach.