« Volver al listado

CVE-2017-4961

Estado: ModificadaAlta (8.8)—

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-4961",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 8.8,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Cloud Foundry Foundation BOSH Release",
          "versions": [
            {
              "status": "affected",
              "version": "Cloud Foundry Foundation BOSH Release"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-06-13T06:29:00.393",
  "references": [
    {
      "url": "https://www.cloudfoundry.org/cve-2017-4961/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.cloudfoundry.org/cve-2017-4961/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-354"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka \"BOSH Director Shell Injection Vulnerabilities.\""
    },
    {
      "lang": "es",
      "value": "Se detectó un problema en las versiones de BOSH versión 261.x anteriores a 261.3 y en todas las versiones de 260.x de Cloud Foundry Foundation. En ciertos casos, un usuario Director identificado puede proporcionar una suma de comprobaciones maliciosa que podría permitirles escalar sus privilegios en la  Máquina Virtual Director, también se conoce como \"BOSH Director Shell Injection Vulnerabilities"
    }
  ],
  "lastModified": "2026-06-17T01:19:38.460",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B8F3F33E-AEE9-4D6B-96F8-908AECBCE525"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF5D0352-286C-4F64-9147-DEBE00F8B00D"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "44842718-23C0-462F-AEA0-0A1112BBF3B6"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D81B883-92C1-40C5-A791-03243CA6A463"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "2D755675-393A-440C-8333-E53CEE9CCB49"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "99AD3D75-6439-43CC-89CE-BA94BB8617A8"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "075C80C7-CF9E-4D0B-8A8F-009DAC9FF84D"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5126E768-3CF2-4E88-AC18-23BAD27EDDAB"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A8AC8AC7-38F4-4106-8805-8F805C257A58"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F460F5ED-2FB6-49B7-9E9F-326388E713C1"
            },
            {
              "criteria": "cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0D858418-DCD2-4463-9330-C9A6C3E99237"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}