Ecosyste.ms: Advisories
An open API service providing security vulnerability metadata for many open source software ecosystems.
Security Advisories: GSA_kwCzR0hTQS1jdzljLXYzdjItOTlobc3uCw
Blind SQL Injection with privileged Cloud Foundry UAA endpoints
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1. An authorized user can use a blind SQL injection attack to query the contents of the UAA database, aka "Blind SQL Injection with privileged UAA endpoints."
Permalink: https://github.com/advisories/GHSA-cw9c-v3v2-99hmJSON: https://advisories.ecosyste.ms/api/v1/advisories/GSA_kwCzR0hTQS1jdzljLXYzdjItOTlobc3uCw
Source: GitHub Advisory Database
Origin: Unspecified
Severity: Moderate
Classification: General
Published: almost 2 years ago
Updated: 2 months ago
CVSS Score: 6.5
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Identifiers: GHSA-cw9c-v3v2-99hm, CVE-2017-4974
References:
- https://nvd.nist.gov/vuln/detail/CVE-2017-4974
- https://github.com/cloudfoundry/uaa/commit/01edea6337c8ddb2ab80906aa1254d3c1dc02fb
- https://github.com/cloudfoundry/uaa/commit/2dbeb9e93e076d71d7f0886dea9f77f23e0b8f3c
- https://github.com/cloudfoundry/uaa/commit/5dc5ca9176ed5baa870680d99f37e7e559dddc5
- https://github.com/cloudfoundry/uaa/commit/74b9b270787aa602196d59d58893c3a6e09816f9
- https://github.com/cloudfoundry/uaa/commit/b6d6526cb89120043d390bf0274cd062e9fc452
- https://web.archive.org/web/20200227163823/http://www.securityfocus.com/bid/99254
- https://www.cloudfoundry.org/cve-2017-4974
- https://github.com/advisories/GHSA-cw9c-v3v2-99hm
Blast Radius: 7.6
Affected Packages
maven:org.cloudfoundry.identity:cloudfoundry-identity-server
Dependent packages: 3Dependent repositories: 15
Downloads:
Affected Version Ranges: >= 3.10.0, < 3.16.0, >= 3.7.0, < 3.9.11, >= 3.0.0, < 3.6.9, >= 2.0.0, < 2.7.4.15
Fixed in: 3.16.0, 3.9.11, 3.6.9, 2.7.4.15
All affected versions: 3.0.0, 3.0.1, 3.1.0, 3.2.0, 3.2.1, 3.3.0, 3.4.0, 3.4.2, 3.4.3, 3.4.4, 3.4.5, 3.5.0, 3.6.0, 3.7.0, 3.7.3, 3.8.0, 3.9.0, 3.9.1, 3.10.0, 3.12.0, 3.13.0, 3.15.0, 3.16.0, 3.18.0, 3.19.0, 3.20.0, 4.1.0, 4.2.0, 4.3.0, 4.4.0, 4.5.0, 4.5.6, 4.5.7, 4.5.8, 4.5.9, 4.6.0, 4.6.1, 4.7.0, 4.7.1, 4.7.2, 4.7.4, 4.7.5, 4.7.6, 4.8.0, 4.8.2, 4.8.3, 4.9.0, 4.10.0, 4.10.1, 4.10.2, 4.11.0, 4.12.0, 4.12.1, 4.12.2, 4.12.3, 4.12.4, 4.13.0, 4.13.1, 4.13.3, 4.13.4, 4.14.0, 4.15.0, 4.16.0, 4.17.0, 4.18.0, 4.19.0, 4.19.2, 4.20.0, 4.21.0, 4.22.0, 4.23.0, 4.24.0, 4.25.0, 4.26.0, 4.27.0, 4.30.0
All unaffected versions: