« Volver al listado

CVE-2017-8048

Estado: ModificadaAlta (7.8)—

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2017-8048",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "MEDIUM",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8.6,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": true
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.8,
          "attackVector": "LOCAL",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "security_alert@emc.com",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "Cloud Controller VM capi-release versions 1.33.0 and later, prior to 1.42.0, cf-release versions 268 and later, prior to 274",
          "versions": [
            {
              "status": "affected",
              "version": "Cloud Controller VM capi-release versions 1.33.0 and later, prior to 1.42.0, cf-release versions 268 and later, prior to 274"
            }
          ]
        }
      ]
    }
  ],
  "published": "2017-10-04T01:29:03.653",
  "references": [
    {
      "url": "https://www.cloudfoundry.org/cve-2017-8048/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security_alert@emc.com"
    },
    {
      "url": "https://www.cloudfoundry.org/cve-2017-8048/",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275."
    },
    {
      "lang": "es",
      "value": "En las versiones de la 1.33.0 hasta la 1.42.0 del desarrollo capi-release y las versiones de la 268 hasta la 274 (no inclusive) del desarrollo cf-release de Cloud Foundry, la solución original para CVE-2017-8033 introduce una regresión de API que permite que un desarrollador de espacio ejecute código arbitrario en la máquina virtual de Cloud Controller abriendo una aplicación especialmente manipulada. NOTA: 274 resuelve la vulnerabilidad pero tiene un error grave que se resuelve en 275."
    }
  ],
  "lastModified": "2026-06-17T01:25:41.527",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:268:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "735E1016-97F0-4286-955F-6017A2F8AD79"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:269:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F021AB15-30F0-46DE-B613-11E3D4C9FD50"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:270:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "55F6F25E-B163-4587-A5B0-38D06E79F9EA"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:271:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C362BD6-2F2B-41F5-85B4-8EF412C52FBD"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:272:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D97DC93C-8944-412F-8F5D-1CE29BA1E53B"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-release:273:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3C4D07FC-7A86-4B9E-BF2C-382BB0DA8F00"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.33.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5EA3D640-F0F2-4F0A-9B7D-6ADD356A0620"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.34.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C9A2F496-2DC2-4715-AE3C-2D1B4F7FC42E"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.35.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "182CF381-85D1-4FD5-A4A7-77ECE267BD01"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.36.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A011CFE7-9F6C-4584-A600-27A0605DD424"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.37.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A2158F3B-2746-4E15-87C5-39CAE6EB2163"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.38.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36AABE9B-DAB9-41CA-AFE2-AC6F8C37F207"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.39.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "664569DC-51E7-4C6E-ACED-D382A261B878"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.40.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BF614F71-E9DF-4B90-B503-1618AA79B707"
            },
            {
              "criteria": "cpe:2.3:a:pivotal:capi-release:1.41.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1960B595-6BAC-489D-9534-6894C3C5F019"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security_alert@emc.com"
}