CVE-2017-8031
Cloud Foundry UAA Denial of Service through client token revocation endpoint
5.3
MEDIUM
CVSS 3.1
EPSS 1.1%
描述
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same client. This occurs only if the client is using opaque tokens or JWT tokens validated using the check_token endpoint. A malicious actor could cause denial of service.
如何修補 CVE-2017-8031
要修補 CVE-2017-8031,請將受影響套件升級到下列已修補版本。
- —升級至 4.7.1 或更新版本
CVE-2017-8031 正在被利用嗎?
低 — EPSS 為 1.1%,目前沒有觀察到大規模利用活動。
受影響套件(1)
- >= 4.6.0, < 4.7.1
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.3 | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H |