{"id":"CVE-2017-4961","details":"An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka \"BOSH Director Shell Injection Vulnerabilities.\"","modified":"2026-08-07T11:31:01.354205574Z","published":"2017-06-13T06:29:00.393Z","database_specific":{"unresolved_ranges":[{"vendor_product":"cloud_foundry:bosh","cpes":["cpe:2.3:a:cloud_foundry:bosh:260.7:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"260.7"},{"last_affected":"260.7"}],"source":"CPE_STRING"}]},"references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/cve-2017-4961/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/bosh","events":[{"introduced":"2541d80f528c80f4c2e7675c8efca6065d386639"},{"last_affected":"523251dee4c4fae1713a3ec0e150f83900fa1efe"}],"database_specific":{"cpe":["cpe:2.3:a:cloud_foundry:bosh:260:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.1:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.2:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.3:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.4:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.5:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:260.6:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:261:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:261.1:*:*:*:*:*:*:*","cpe:2.3:a:cloud_foundry:bosh:261.2:*:*:*:*:*:*:*"],"extracted_events":[{"introduced":"260"},{"last_affected":"260"},{"introduced":"260.1"},{"last_affected":"260.1"},{"introduced":"260.2"},{"last_affected":"260.2"},{"introduced":"260.3"},{"last_affected":"260.3"},{"introduced":"260.4"},{"last_affected":"260.4"},{"introduced":"260.5"},{"last_affected":"260.5"},{"introduced":"260.6"},{"last_affected":"260.6"},{"introduced":"261"},{"last_affected":"261"},{"introduced":"261.1"},{"last_affected":"261.1"},{"introduced":"261.2"},{"last_affected":"261.2"}],"source":"CPE_STRING"}}],"versions":["260","260.1","260.2","260.3","260.6","261","261.1","261.2"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-4961.json"}}],"schema_version":"1.8.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}