{"id":"CVE-2017-14388","details":"Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide an image layer that GrootFS would consider to be the Ubuntu base layer.","modified":"2026-07-08T12:06:29.870175Z","published":"2017-11-13T17:29:00.537Z","references":[{"type":"REPORT","url":"https://www.cloudfoundry.org/cve-2017-14388/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/grootfs","events":[{"introduced":"243b25994be8786632dc5cddbf543f1b9af8cc93"},{"last_affected":"4c92dfed6eb4b36b2e3f1e449cae0df48d32cbe0"}],"database_specific":{"source":"CPE_STRING","cpe":["cpe:2.3:a:pivotal_software:grootfs:0.3.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.4.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.5.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.6.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.7.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.8.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.9.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.10.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.11.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.12.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.13.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.14.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.15.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.16.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.17.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.17.1:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.18.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.19.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.20.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.21.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.24.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.25.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.26.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.27.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.28.0:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.28.1:*:*:*:*:*:*:*","cpe:2.3:a:pivotal_software:grootfs:0.29.0:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"0.3.0"},{"last_affected":"0.3.0"},{"introduced":"0.4.0"},{"last_affected":"0.4.0"},{"introduced":"0.5.0"},{"last_affected":"0.5.0"},{"introduced":"0.6.0"},{"last_affected":"0.6.0"},{"introduced":"0.7.0"},{"last_affected":"0.7.0"},{"introduced":"0.8.0"},{"last_affected":"0.8.0"},{"introduced":"0.9.0"},{"last_affected":"0.9.0"},{"introduced":"0.10.0"},{"last_affected":"0.10.0"},{"introduced":"0.11.0"},{"last_affected":"0.11.0"},{"introduced":"0.12.0"},{"last_affected":"0.12.0"},{"introduced":"0.13.0"},{"last_affected":"0.13.0"},{"introduced":"0.14.0"},{"last_affected":"0.14.0"},{"introduced":"0.15.0"},{"last_affected":"0.15.0"},{"introduced":"0.16.0"},{"last_affected":"0.16.0"},{"introduced":"0.17.0"},{"last_affected":"0.17.0"},{"introduced":"0.17.1"},{"last_affected":"0.17.1"},{"introduced":"0.18.0"},{"last_affected":"0.18.0"},{"introduced":"0.19.0"},{"last_affected":"0.19.0"},{"introduced":"0.20.0"},{"last_affected":"0.20.0"},{"introduced":"0.21.0"},{"last_affected":"0.21.0"},{"introduced":"0.24.0"},{"last_affected":"0.24.0"},{"introduced":"0.25.0"},{"last_affected":"0.25.0"},{"introduced":"0.26.0"},{"last_affected":"0.26.0"},{"introduced":"0.27.0"},{"last_affected":"0.27.0"},{"introduced":"0.28.0"},{"last_affected":"0.28.0"},{"introduced":"0.28.1"},{"last_affected":"0.28.1"},{"introduced":"0.29.0"},{"last_affected":"0.29.0"}]}}],"versions":["0.10.0","0.11.0","0.12.0","0.13.0","0.14.0","0.15.0","0.16.0","0.17.0","0.17.1","0.18.0","0.19.0","0.20.0","0.21.0","0.24.0","0.25.0","0.26.0","0.27.0","0.28.0","0.28.1","0.29.0","0.3.0","0.4.0","0.5.0","0.6.0","0.7.0","0.8.0","0.9.0","v0.29.0","v0.28.1","v0.28.0","v0.27.0","v0.26.0","v0.25.0","v0.24.0","v0.21.0","v0.20.0","v0.19.0","v0.18.0","v0.17.1","v0.17.0","v0.16.0","v0.15.0","v0.14.0","v0.13.0","v0.12.0","v0.11.0","v0.8.0","v0.7.0","v0.6.0","v0.5.0","v0.4.0","v0.3.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-14388.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}