Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:F387FF8A7562E6D593A428E8C515F0E4
HistoryJul 19, 2017 - 12:00 a.m.

CVE-2017-8033: Cloud Controller API filesystem traversal vulnerability | Cloud Foundry

2017-07-1900:00:00
Cloud Foundry
www.cloudfoundry.org
31

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.2%

Severity

High

Vendor

Cloud Foundry Foundation

Versions Affected

  • CAPI-release versions prior to v1.35.0
  • cf-release versions prior to v268

Description

A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially-crafted application that can write arbitrary files to the Cloud Controller VM.

Mitigation

Users of affected versions should apply the following mitigation or upgrade:

  • Upgrade to Cloud Foundry v268 [1] or later
  • For standalone component users:
    • Upgrade to CAPI-release 1.35.0 or later [2]

Credit

This vulnerability was responsibly reported by the GE Digital Security Team.

References

History

2017-07-19: Initial vulnerability report published

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

30.2%

Related for CFOUNDRY:F387FF8A7562E6D593A428E8C515F0E4