Vulnerability Description
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudfoundry | Cloud Foundry Uaa Bosh | 21 |
| Pivotal Software | Cloud Foundry | 247.0 |
| Pivotal Software | Cloud Foundry Uaa | 3.9.0 |
References
- http://www.securityfocus.com/bid/96780Third Party AdvisoryVDB Entry
- https://www.cloudfoundry.org/cve-2017-4960/Vendor Advisory
- http://www.securityfocus.com/bid/96780Third Party AdvisoryVDB Entry
- https://www.cloudfoundry.org/cve-2017-4960/Vendor Advisory
FAQ
What is CVE-2017-4960?
CVE-2017-4960 is a vulnerability with a CVSS score of 7.5 (HIGH). An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth ...
How severe is CVE-2017-4960?
CVE-2017-4960 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-4960?
Check the references section above for vendor advisories and patch information. Affected products include: Cloudfoundry Cloud Foundry Uaa Bosh, Pivotal Software Cloud Foundry, Pivotal Software Cloud Foundry Uaa.