Security Advisory

CVE-2017-8034

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2017-07-17 14:00:00
Last updated 2024-08-05 16:19:29
Assigner dell
State PUBLISHED

Description

The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.