CVE-2017-14388
Summary
| CVE | CVE-2017-14388 |
|---|---|
| State | PUBLISHED |
| Assigner | dell |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-11-13 17:29:00 UTC |
| Updated | 2025-04-20 01:37:25 UTC |
| Description | Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide an image layer that GrootFS would consider to be the Ubuntu base layer. |
Risk And Classification
Primary CVSS: v3.0 7.8 HIGH from [email protected]
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS: 0.001820000 probability, percentile 0.394590000 (date 2026-05-13)
Problem Types: CWE-20 | Does not validate DiffIDs
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.0 | [email protected] | Primary | 7.8 | HIGH | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
| 2.0 | [email protected] | Primary | 6.8 | AV:N/AC:M/Au:N/C:P/I:P/A:P |
CVSS v3.0 Breakdown
Attack Vector
LocalAttack Complexity
LowPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
HighCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
PartialIntegrity
PartialAvailability
PartialAV:N/AC:M/Au:N/C:P/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Pivotal Software | Grootfs | 0.10.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.11.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.12.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.13.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.14.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.15.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.16.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.17.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.17.1 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.18.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.19.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.20.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.21.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.24.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.25.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.26.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.27.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.28.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.28.1 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.29.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.3.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.4.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.5.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.6.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.7.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.8.0 | All | All | All |
| Application | Pivotal Software | Grootfs | 0.9.0 | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Na | GrootFS Release GrootFS Release 0.3.x Versions Prior To 0.30.0 | affected GrootFS release GrootFS release 0.3.x versions prior to 0.30.0 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| CVE-2017-14388: GrootFS doesn't validate DiffIDs | Cloud Foundry | af854a3a-2127-422b-91ae-364da2661108 | www.cloudfoundry.org | Issue Tracking, Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.