Re: CVE-2017-4992: Privilege escalation with user invitations


Alex Tomlins <alex.tomlins@...>
 

On 19/05/2017 19:19, Molly Crowther wrote:
Please see the following link for information on *critical* UAA
CVE CVE-2017-4992: Privilege escalation with user invitations

We tried to include more information this time about how to tell if
you are exploited, please let me know or reach out in the Cloud
Foundry slack if you have any further questions.
I'm not seeing this information included in the CVE announcement. Can
you point me to where this is published please?

thanks,
Alex

https://www.cloudfoundry.org/cve-2017-4992/

Friendly reminder that you can subscribe to new Cloud Foundry security
issues at: https://www.cloudfoundry.org/category/security/feed/
<https://www.cloudfoundry.org/category/security/feed/>

Thanks,
Molly Crowther
Cloud Foundry Foundation Security Team

Join {cf-dev@lists.cloudfoundry.org to automatically receive all group messages.