An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1. An authorized user can use a blind SQL injection attack to query the contents of the UAA database, aka "Blind SQL Injection with privileged UAA endpoints."
{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "v257"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "4.2.0"
},
{
"introduced": "0"
},
{
"last_affected": "2.2.5.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.1"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.2"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.3"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.4"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.5"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.6"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.7"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.8"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.9"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.11"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.12"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.13"
},
{
"introduced": "0"
},
{
"last_affected": "2.7.4.14"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.7"
},
{
"introduced": "0"
},
{
"last_affected": "3.6.8"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.1"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.2"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.3"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.4"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.5"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.6"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.7"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.8"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.9"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.10"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.12"
},
{
"introduced": "0"
},
{
"last_affected": "3.9.13"
}
]
}{
"versions": [
{
"introduced": "0"
},
{
"last_affected": "30"
},
{
"introduced": "0"
},
{
"last_affected": "13.1"
},
{
"introduced": "0"
},
{
"last_affected": "13.2"
},
{
"introduced": "0"
},
{
"last_affected": "13.3"
},
{
"introduced": "0"
},
{
"last_affected": "13.4"
},
{
"introduced": "0"
},
{
"last_affected": "13.5"
},
{
"introduced": "0"
},
{
"last_affected": "13.6"
},
{
"introduced": "0"
},
{
"last_affected": "13.7"
},
{
"introduced": "0"
},
{
"last_affected": "13.8"
},
{
"introduced": "0"
},
{
"last_affected": "13.9"
},
{
"introduced": "0"
},
{
"last_affected": "13.10"
},
{
"introduced": "0"
},
{
"last_affected": "13.11"
},
{
"introduced": "0"
},
{
"last_affected": "13.12"
},
{
"introduced": "0"
},
{
"last_affected": "24"
},
{
"introduced": "0"
},
{
"last_affected": "24.1"
},
{
"introduced": "0"
},
{
"last_affected": "24.2"
},
{
"introduced": "0"
},
{
"last_affected": "24.3"
},
{
"introduced": "0"
},
{
"last_affected": "24.4"
},
{
"introduced": "0"
},
{
"last_affected": "24.5"
},
{
"introduced": "0"
},
{
"last_affected": "24.6"
},
{
"introduced": "0"
},
{
"last_affected": "24.7"
},
{
"introduced": "0"
},
{
"last_affected": "30.1"
},
{
"introduced": "0"
},
{
"last_affected": "30.2"
},
{
"introduced": "0"
},
{
"last_affected": "30.3"
}
]
}