Description
An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through v26. There is a potential to subject the UAA OAuth clients to a denial of service attack.
Remediation
References
http://www.securityfocus.com/bid/96780
https://www.cloudfoundry.org/cve-2017-4960/
Related Vulnerabilities
CVE-2021-23397 Vulnerability in npm package @ianwalter/merge
CVE-2019-10313 Vulnerability in maven package org.jenkins-ci.plugins:twitter
CVE-2022-25921 Vulnerability in npm package morgan-json
CVE-2022-40151 Vulnerability in maven package com.thoughtworks.xstream:xstream
CVE-2020-2264 Vulnerability in maven package org.jenkins-ci.plugins:custom-job-icon