Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2017-4972: CVE-2017-4972: Blind SQL Injection in UAA | Cloud Foundry

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior to v24.7, and other versions prior to v30. An attacker can use a blind SQL injection attack to query the contents of the UAA database.

CVE
#sql#vulnerability#git

****CVE-2017-4972: Blind SQL Injection in UAA********Severity****

High

****Vendor****

Cloud Foundry Foundation

****Versions Affected****

  • cf-release versions prior to v257
  • UAA release:
    • 2.x versions prior to v2.7.4.14
    • 3.6.x versions prior to v3.6.8
    • 3.9.x versions prior to v3.9.10
    • Other versions prior to v3.15.0
  • UAA bosh release (uaa-release):
    • 13.x versions prior to v13.12
    • 24.x versions prior to v24.7
    • Other versions prior to v30

****Description****

An attacker can use a blind SQL injection attack to query the contents of the UAA database.

****Mitigation****

OSS users are strongly encouraged to follow one of the mitigations below:

  • Upgrade to Cloud Foundry v257 [1] or later
  • For standalone UAA users:
    • For users using UAA Version 3.0.0 – 3.14.0, please upgrade to UAA Release to v3.15.0 [2] or v3.9.10 [3] or v3.6.8 [4]
    • For users using standalone UAA Version 2.X.X, please upgrade to UAA Release to v2.7.4.14 [5]
    • For users using UAA-Release (UAA bosh release), please upgrade to UAA-Release v30 [6] if upgrading to v3.15.0 [2] or v24.7 [7] if upgrading to v3.9.10 [3] and v13.12 [8] if upgrading to v3.6.8 [4]

****References****

  • [1] https://github.com/cloudfoundry/cf-release/releases
  • [2] https://github.com/cloudfoundry/uaa/releases/tag/3.15.0
  • [3] https://github.com/cloudfoundry/uaa/releases/tag/3.9.10
  • [4] https://github.com/cloudfoundry/uaa/releases/tag/3.6.8
  • [5] https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.14
  • [6] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=30
  • [7] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=24.7
  • [8] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=13.12

****History****

2017-04-19: Initial vulnerability report published

Sign up for the
Cloud Foundry Newsletter today!

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907