Headline
CVE-2017-4974: CVE-2017-4974: Blind SQL Injection with privileged UAA endpoints | Cloud Foundry
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1. An authorized user can use a blind SQL injection attack to query the contents of the UAA database, aka “Blind SQL Injection with privileged UAA endpoints.”
CVE-2017-4974: Blind SQL Injection with privileged UAA endpoints****Severity
High
Vendor
Cloud Foundry Foundation
Versions Affected
- cf-release versions prior to v258
- UAA release:
- 2.x versions prior to v2.7.4.15
- 3.6.x versions prior to v3.6.9
- 3.9.x versions prior to v3.9.11
- Other versions prior to v3.16.0
- UAA bosh release (uaa-release):
- 13.x versions prior to v13.13
- 24.x versions prior to v24.8
- Other versions prior to v30.1
Description
An authorized user can use a blind SQL injection attack to query the contents of the UAA database.
Mitigation
OSS users are strongly encouraged to follow one of the mitigations below:
- Upgrade to Cloud Foundry v258 [1] or later
- For standalone UAA users:
- For users using UAA Version 3.0.0 – 3.14.0, please upgrade to UAA Release to v3.16.0 [2] or v3.9.11 [3] or v3.6.9 [4]
- For users using standalone UAA Version 2.X.X, please upgrade to UAA Release to v2.7.4.15 [5]
- For users using UAA-Release (UAA bosh release), please upgrade to UAA-Release v30.1 [6] if upgrading to v3.16.0 [2] or v24.8 [7] if upgrading to v3.9.11 [3] and v13.13 [8] if upgrading to v3.6.9 [4]
References
- [1] https://github.com/cloudfoundry/cf-release/releases
- [2] https://github.com/cloudfoundry/uaa/releases/tag/3.16.0
- [3] https://github.com/cloudfoundry/uaa/releases/tag/3.9.11
- [4] https://github.com/cloudfoundry/uaa/releases/tag/3.6.9
- [5] https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.15
- [6] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=30.1
- [7] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=24.8
- [8] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=13.13
History
2017-05-01: Initial vulnerability report published
Sign up for the
Cloud Foundry Newsletter today!