NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
84650  CVE-2017-4964  Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the director, aka a CPI code injection vulnerability.    4.6  Medium  2017-04-27  2017-04-12  View
86928  CVE-2017-4963  An issue was discovered in Cloud Foundry Foundation Cloud Foundry release v252 and earlier versions, UAA stand-alone release v2.0.0 - v2.7.4.12 & v3.0.0 - v3.11.0, and UAA bosh release v26 & earlier versions. UAA is vulnerable to session fixation when configured to authenticate against external SAML or OpenID Connect based identity providers.    6.8  Medium  2017-07-18  2017-07-03  View
86927  CVE-2017-4961  An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka BOSH Director Shell Injection Vulnerabilities.    6.5  Medium  2017-06-23  2017-06-22  View
83183  CVE-2017-4960  An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.    Medium  2017-03-18  2017-03-15  View
86926  CVE-2017-4959  An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to take over the account of another user, causing account lockout and potential escalation of privileges.    6.5  Medium  2017-07-18  2017-07-03  View

Page 523 of 17672, showing 5 records out of 88360 total, starting on record 2611, ending on 2615

Actions