CVE-2017-4961

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
References
Link Resource
https://www.cloudfoundry.org/cve-2017-4961/ Vendor Advisory
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*

Information

Published : 2017-06-12 23:29

Updated : 2019-10-02 17:03


NVD link : CVE-2017-4961

Mitre link : CVE-2017-4961


JSON object : View

CWE
CWE-354

Improper Validation of Integrity Check Value

Advertisement

dedicated server usa

Products Affected

cloud_foundry

  • bosh