Description
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-17001 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/cve-2017-8034/ |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-05T16:19:29.540Z
Reserved: 2017-04-21T00:00:00.000Z
Link: CVE-2017-8034
No data.
Status : Modified
Published: 2017-07-17T14:29:01.280
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-8034
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD