PT-2017-16231 · Cloud Foundry Foundation · Bosh Azure Cpi
Paul Nikonowicz
+1
·
Publicado
2017-04-06
·
Atualizado
2021-05-27
·
CVE-2017-4964
CVSS v3.1
8.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Foundation BOSH Azure CPI version v22
Description
The issue allows a maliciously crafted stemcell to potentially execute arbitrary code on VMs created by the director. This is described as a CPI code injection issue.
Recommendations
For Cloud Foundry Foundation BOSH Azure CPI version v22, update to a version that includes the fix for this issue to prevent potential code injection.
Correção
Code Injection
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bosh Azure Cpi