CVE-2017-8034: Medium severity Cloudfoundry Capi-release vulnerability
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8034?
CVE-2017-8034 is considered a medium severity vulnerability due to improper validation of JSON Web Tokens.
How do I fix CVE-2017-8034?
To remediate CVE-2017-8034, upgrade Cloud Foundry's CAPI-release to v1.32.0 or newer, Routing-release to v0.159.0 or newer, and CF-release to v267 or newer.
What is the impact of CVE-2017-8034?
CVE-2017-8034 can allow unauthorized access to applications if the issuer of JSON Web Tokens is not properly validated.
Which versions are affected by CVE-2017-8034?
CVE-2017-8034 affects CAPI-release versions prior to v1.32.0, Routing-release versions prior to v0.159.0, and CF-release versions prior to v267.
Is there a workaround for CVE-2017-8034?
There are no known workarounds for CVE-2017-8034; the recommended action is to update to the latest versions.