CyberSec.Space Logo
Back to CVE Browser

CVE-2016-8218

CRITICAL
9.8
CVSS Severity Score
EPSS Score0.0180%
EPSS Percentile32.52th
PublishedJun 13, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

Affected Platforms (CPE)

πŸ“¦
Cloudfoundry

Cf Release

<= 203
πŸ“¦
Cloudfoundry

Cf Release

= 204
πŸ“¦
Cloudfoundry

Cf Release

= 205
πŸ“¦
Cloudfoundry

Cf Release

= 206
πŸ“¦
Cloudfoundry

Cf Release

= 207
πŸ“¦
Cloudfoundry

Cf Release

= 208
πŸ“¦
Cloudfoundry

Cf Release

= 209
πŸ“¦
Cloudfoundry

Cf Release

= 210
πŸ“¦
Cloudfoundry

Cf Release

= 211
πŸ“¦
Cloudfoundry

Cf Release

= 212
πŸ“¦
Cloudfoundry

Cf Release

= 213
πŸ“¦
Cloudfoundry

Cf Release

= 214
πŸ“¦
Cloudfoundry

Cf Release

= 215
πŸ“¦
Cloudfoundry

Cf Release

= 217
πŸ“¦
Cloudfoundry

Cf Release

= 218
πŸ“¦
Cloudfoundry

Cf Release

= 219
πŸ“¦
Cloudfoundry

Cf Release

= 220
πŸ“¦
Cloudfoundry

Cf Release

= 221
πŸ“¦
Cloudfoundry

Cf Release

= 222
πŸ“¦
Cloudfoundry

Cf Release

= 223
πŸ“¦
Cloudfoundry

Cf Release

= 224
πŸ“¦
Cloudfoundry

Cf Release

= 225
πŸ“¦
Cloudfoundry

Cf Release

= 226
πŸ“¦
Cloudfoundry

Cf Release

= 227
πŸ“¦
Cloudfoundry

Cf Release

= 228
πŸ“¦
Cloudfoundry

Cf Release

= 229
πŸ“¦
Cloudfoundry

Cf Release

= 230
πŸ“¦
Cloudfoundry

Cf Release

= 231
πŸ“¦
Cloudfoundry

Routing Release

<= 0.141.0

References & Advisories

Related Vulnerabilities