CVE-2017-4961

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."
References
Link Resource
https://www.cloudfoundry.org/cve-2017-4961/ Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*
cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*

History

No history.

Information

Published : 2017-06-13 06:29

Updated : 2023-12-10 12:15


NVD link : CVE-2017-4961

Mitre link : CVE-2017-4961

CVE.ORG link : CVE-2017-4961


JSON object : View

Products Affected

cloud_foundry

  • bosh
CWE
CWE-354

Improper Validation of Integrity Check Value