CVE-2017-4961

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*

History

21 Nov 2024, 03:26

Type Values Removed Values Added
References () https://www.cloudfoundry.org/cve-2017-4961/ - Vendor Advisory () https://www.cloudfoundry.org/cve-2017-4961/ - Vendor Advisory

Information

Published : 2017-06-13 06:29

Updated : 2024-11-21 03:26


NVD link : CVE-2017-4961

Mitre link : CVE-2017-4961

CVE.ORG link : CVE-2017-4961


JSON object : View

Products Affected

cloud_foundry

  • bosh
CWE
CWE-354

Improper Validation of Integrity Check Value