CVE-2017-4959: High severity pivotal elastic runtime vulnerability
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and potential escalation of privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4959?
CVE-2017-4959 has been assigned a medium severity rating due to its potential to allow unauthorized user account takeover.
How do I fix CVE-2017-4959?
To fix CVE-2017-4959, upgrade Pivotal Cloud Foundry Elastic Runtime to versions 1.8.29 or 1.9.7 and above.
What versions are affected by CVE-2017-4959?
CVE-2017-4959 affects Pivotal Cloud Foundry Elastic Runtime versions 1.8.x prior to 1.8.29 and 1.9.x prior to 1.9.7.
What type of vulnerability is CVE-2017-4959?
CVE-2017-4959 is a user account takeover vulnerability that can be exploited by an authorized user.
Can I mitigate CVE-2017-4959 without upgrading?
There are no known workarounds for CVE-2017-4959; upgrading to the patched versions is the recommended approach.