GHSA-jcmh-x32v-7mgf · Severity: critical · Ecosystem: maven — Cloud Foundry UAA privilege escalation with user invitations
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior to v24.10, 30.x versions prior to 30.3, and other versions prior to v37. There is privilege escalation (arbitrary password reset) with user invitations.
Conclusion & alert: CVE-2017-4992 is rated Moderate Risk (62.1/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.17%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 0.40% | 1.17% | +0.77% |
| 2 | 2025-03-30 | 0.33% | 0.40% | +0.07% |
| 3 | 2025-03-29 | — | 0.33% | — |
Full EPSS history (7 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.1 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
GHSA-jcmh-x32v-7mgf · Severity: critical · Ecosystem: maven — Cloud Foundry UAA privilege escalation with user invitations
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| cloudfoundry | cf-release | <= 260 | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | <= 27 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:*:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.1 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.1:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.2 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.2:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.3 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.3:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.4 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.4:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.5 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.5:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.6 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.6:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.7 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.7:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.8 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.8:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.9 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.9:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.10 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.10:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.11 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.11:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.12 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.12:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.13 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.13:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 13.14 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:13.14:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.1 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.1:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.2 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.2:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.3 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.3:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.4 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.4:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.5 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.5:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.6 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.6:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.7 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.7:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.8 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.8:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 24.9 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:24.9:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 30 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:30:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 30.1 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:30.1:*:*:*:*:*:*:* |
| cloudfoundry | cloud_foundry_uaa_bosh | 30.2 | cpe:2.3:a:cloudfoundry:cloud_foundry_uaa_bosh:30.2:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | <= 4.2.0 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:*:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.2.5.4 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.2.5.4:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.1 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.1:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.2 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.2:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.3 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.3:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.1 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.1:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.2 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.2:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.3 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.3:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.4 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.4:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.5 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.5:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.6 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.6:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.7 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.7:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.8 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.8:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.9 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.9:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.11 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.11:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.12 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.12:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.13 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.13:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.14 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.14:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.15 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.15:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 2.7.4.16 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:2.7.4.16:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.1 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.1:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.2 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.2:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.3 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.3:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.4 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.4:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.5 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.5:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.6 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.6:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.7 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.7:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.8 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.8:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.9 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.9:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.6.10 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.6.10:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.1 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.1:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.2 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.2:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.3 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.3:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.4 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.4:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.5 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.5:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.6 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.6:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.7 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.7:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.8 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.8:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.9 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.9:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.10 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.10:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.11 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.11:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.12 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.12:*:*:*:*:*:*:* |
| pivotal_software | cloud_foundry_uaa | 3.9.13 | cpe:2.3:a:pivotal_software:cloud_foundry_uaa:3.9.13:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://www.cloudfoundry.org/cve-2017-4992/ | Vendor Advisory |