CVE Vulnerabilities

CVE-2017-4960

Published: Mar 10, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.

Affected Software

NameVendorStart VersionEnd Version
Cloud_foundry_uaa_boshCloudfoundry21 (including)21 (including)
Cloud_foundry_uaa_boshCloudfoundry22 (including)22 (including)
Cloud_foundry_uaa_boshCloudfoundry23 (including)23 (including)
Cloud_foundry_uaa_boshCloudfoundry24 (including)24 (including)
Cloud_foundry_uaa_boshCloudfoundry24.1 (including)24.1 (including)
Cloud_foundry_uaa_boshCloudfoundry24.2 (including)24.2 (including)
Cloud_foundry_uaa_boshCloudfoundry24.3 (including)24.3 (including)
Cloud_foundry_uaa_boshCloudfoundry24.4 (including)24.4 (including)
Cloud_foundry_uaa_boshCloudfoundry24.5 (including)24.5 (including)
Cloud_foundry_uaa_boshCloudfoundry24.6 (including)24.6 (including)
Cloud_foundry_uaa_boshCloudfoundry25 (including)25 (including)
Cloud_foundry_uaa_boshCloudfoundry26 (including)26 (including)
Cloud_foundryPivotal_software247.0 (including)247.0 (including)
Cloud_foundryPivotal_software248.0 (including)248.0 (including)
Cloud_foundryPivotal_software249.0 (including)249.0 (including)
Cloud_foundryPivotal_software250.0 (including)250.0 (including)
Cloud_foundryPivotal_software251.0 (including)251.0 (including)
Cloud_foundryPivotal_software252.0 (including)252.0 (including)
Cloud_foundry_uaaPivotal_software3.9.0 (including)3.9.0 (including)
Cloud_foundry_uaaPivotal_software3.9.1 (including)3.9.1 (including)
Cloud_foundry_uaaPivotal_software3.9.2 (including)3.9.2 (including)
Cloud_foundry_uaaPivotal_software3.9.3 (including)3.9.3 (including)
Cloud_foundry_uaaPivotal_software3.9.4 (including)3.9.4 (including)
Cloud_foundry_uaaPivotal_software3.9.5 (including)3.9.5 (including)
Cloud_foundry_uaaPivotal_software3.9.6 (including)3.9.6 (including)
Cloud_foundry_uaaPivotal_software3.9.7 (including)3.9.7 (including)
Cloud_foundry_uaaPivotal_software3.9.8 (including)3.9.8 (including)
Cloud_foundry_uaaPivotal_software3.10.0 (including)3.10.0 (including)
Cloud_foundry_uaaPivotal_software3.11.0 (including)3.11.0 (including)

References