CVE-2017-4961: High severity bosh vulnerability
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4961?
CVE-2017-4961 is considered a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2017-4961?
To fix CVE-2017-4961, upgrade to BOSH Release 261.3 or later versions.
What versions of BOSH are affected by CVE-2017-4961?
CVE-2017-4961 affects all 260.x versions and BOSH Release 261.x versions prior to 261.3.
What is the impact of CVE-2017-4961?
The impact of CVE-2017-4961 allows authenticated users to escalate their privileges on the Director VM.
Who is at risk from CVE-2017-4961?
Authenticated Director users of affected Cloud Foundry BOSH versions are at risk from CVE-2017-4961.