PT-2017-13437 · Cloud Foundry · Cf-Deployment+3

Publicado

2017-11-28

·

Atualizado

2021-05-25

·

CVE-2017-14389

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions capi-release versions prior to 1.45.0 cf-release versions prior to v280 cf-deployment versions prior to v1.0.0
Description An issue allows space developers to create subdomains to an already existing route that belongs to a different user in a different org and space, also known as an "Application Subdomain Takeover." This occurs because the Cloud Controller does not prevent such actions.
Recommendations For capi-release versions prior to 1.45.0, update to version 1.45.0 or later. For cf-release versions prior to v280, update to version v280 or later. For cf-deployment versions prior to v1.0.0, update to version v1.0.0 or later.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-14389

Produtos afetados

Cloud Controller
Capi-Release
Cf-Deployment
Cf-Release