CVE-2017-4991: UAA password reset vulnerability
Severity
High
Vendor
Cloud Foundry Foundation
Versions Affected
- cf-release versions prior to v260
- UAA release:
- 2.x versions prior to v2.7.4.16
- 3.6.x versions prior to v3.6.10
- 3.9.x versions prior to v3.9.12
- Other versions prior to v3.17.0
- UAA bosh release (uaa-release):
- 13.x versions prior to v13.14
- 24.x versions prior to v24.9
- 30.x versions prior to 30.2
- Other versions prior to v36
Description
Privileged users in one zone are allowed to perform reset password for users in a different zone.
Mitigation
Users of affected versions should apply the following mitigation or upgrade:
- Please note: A foundation is affected by this issue only if it is utilizing multiple zones in UAA.
- Upgrade to Cloud Foundry v260 [1] or later
For standalone UAA users:
- For users using UAA Version 3.0.0 – 3.14.0, please upgrade to UAA Release to v3.17.0 [2] or v3.9.12 [3] or v3.6.10 [4]
- For users using standalone UAA Version 2.X.X, please upgrade to UAA Release to v2.7.4.16 [5]
- For users using UAA-Release (UAA bosh release), please upgrade to UAA-Release v30.2 [6] if upgrading to v3.17.0 [2] or v24.9 [7] if upgrading to v3.9.12 [3] and v13.14 [8] if upgrading to v3.6.10 [4]
- For users using the latest version, please upgrade to v36 [9].
Credit
This vulnerability was responsibly reported by the GE Digital Security Team.
References
- [1] https://github.com/cloudfoundry/cf-release/releases
- [2] https://github.com/cloudfoundry/uaa/releases/tag/3.17.0
- [3] https://github.com/cloudfoundry/uaa/releases/tag/3.9.12
- [4] https://github.com/cloudfoundry/uaa/releases/tag/3.6.10
- [5] https://github.com/cloudfoundry/uaa/releases/tag/2.7.4.16
- [6] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=30.2
- [7] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=24.9
- [8] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=13.14
- [9] http://bosh.io/releases/github.com/cloudfoundry/uaa-release?version=36
History
2017-05-17: Initial vulnerability report published
2017-05-17: Description and title updated
2017-11-21: Updated mitigation with information about zones