CVE-2017-4974: Cloudfoundry Cf-Release

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1. An authorized user can use a blind SQL injection attack to query the contents of the UAA database, aka "Blind SQL Injection with privileged UAA endpoints."

Affected products

  • Cloudfoundry Cf-Release: up to and including v257
  • Cloudfoundry Cloud Foundry Uaa Bosh: up to and including 30; version 13.1 only; version 13.2 only; version 13.3 only; version 13.4 only; version 13.5 only; …
  • Pivotal Software Cloud Foundry Uaa: up to and including 4.2.0; version 2.2.5.4 only; version 2.7.1 only; version 2.7.2 only; version 2.7.3 only; version 2.7.4 only; …

Published 2017-06-13. Last modified 2026-06-17.