PT-2017-18090 · Cloud Foundry · Capi-Release+1

Publicado

2017-10-03

·

Atualizado

2021-08-10

·

CVE-2017-8048

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry capi-release versions 1.33.0 through 1.41.x Cloud Foundry cf-release versions 268 through 273
Description The issue allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application, due to an API regression introduced by the original fix for a previous issue.
Recommendations For Cloud Foundry capi-release versions 1.33.0 through 1.41.x, update to version 1.42.0 or later. For Cloud Foundry cf-release versions 268 through 273, update to version 275.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2017-8048

Produtos afetados

Capi-Release
Cf-Release