CVE-2017-4991: High severity Cloudfoundry Cf-release vulnerability
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions prior to v24.9, 30.x versions prior to 30.2, and other versions prior to v36. Privileged users in one zone are allowed to perform a password reset for users in a different zone.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4991?
CVE-2017-4991 is classified as a critical vulnerability that affects multiple versions of Cloud Foundry Foundation software.
How do I fix CVE-2017-4991?
To fix CVE-2017-4991, upgrade to the recommended versions: 3.17.0 for cloudfoundry-identity-server, 3.9.12, or 3.6.10, depending on the specific UAA version in use.
Which versions are affected by CVE-2017-4991?
CVE-2017-4991 affects cf-release versions earlier than 260 and UAA release versions before 2.7.4.16, 3.6.10, and 3.9.12.
What systems are impacted by CVE-2017-4991?
CVE-2017-4991 impacts various versions of Cloud Foundry UAA and cf-release, particularly those mentioned and prior to specified patches.
Is there a way to check for CVE-2017-4991 on my system?
Yes, you can check your current Cloud Foundry and UAA versions against the lists provided in the CVE report to determine if your system is vulnerable.