9.8
CVE-2016-8218
- EPSS 0.59%
- Published 13.06.2017 06:29:00
- Last modified 20.04.2025 01:37:25
- Source security_alert@emc.com
- Teams watchlist Login
- Open Login
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.
Data is provided by the National Vulnerability Database (NVD)
Cloudfoundry ≫ Cf-release Version <= 203
Cloudfoundry ≫ Cf-release Version204
Cloudfoundry ≫ Cf-release Version205
Cloudfoundry ≫ Cf-release Version206
Cloudfoundry ≫ Cf-release Version207
Cloudfoundry ≫ Cf-release Version208
Cloudfoundry ≫ Cf-release Version209
Cloudfoundry ≫ Cf-release Version210
Cloudfoundry ≫ Cf-release Version211
Cloudfoundry ≫ Cf-release Version212
Cloudfoundry ≫ Cf-release Version213
Cloudfoundry ≫ Cf-release Version214
Cloudfoundry ≫ Cf-release Version215
Cloudfoundry ≫ Cf-release Version217
Cloudfoundry ≫ Cf-release Version218
Cloudfoundry ≫ Cf-release Version219
Cloudfoundry ≫ Cf-release Version220
Cloudfoundry ≫ Cf-release Version221
Cloudfoundry ≫ Cf-release Version222
Cloudfoundry ≫ Cf-release Version223
Cloudfoundry ≫ Cf-release Version224
Cloudfoundry ≫ Cf-release Version225
Cloudfoundry ≫ Cf-release Version226
Cloudfoundry ≫ Cf-release Version227
Cloudfoundry ≫ Cf-release Version228
Cloudfoundry ≫ Cf-release Version229
Cloudfoundry ≫ Cf-release Version230
Cloudfoundry ≫ Cf-release Version231
Cloudfoundry ≫ Routing-release Version <= 0.141.0
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.59% | 0.665 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.