PT-2017-6524 · Pivotal · Pivotal Cloud Foundry (Pcf) Elastic Runtime+1
Publicado
2017-05-25
·
Atualizado
2021-08-25
·
CVE-2015-1834
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:N/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry cf-release versions prior to v208
Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2
Description
A path traversal issue was identified in the Cloud Controller component. This issue allows an attacker to access files and directories outside the web root folder by injecting relative file paths, such as '../' sequences, into a certain parameter of the file path. This can lead to disallowed reading or execution of arbitrary system commands. A remote authenticated attacker can exploit this issue to upload arbitrary files to the server running a Cloud Controller instance, outside the isolated application container.
Recommendations
For cf-release versions prior to v208, update to version v208 or later to resolve the issue.
For Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2, update to version 1.4.2 or later to resolve the issue.
As a temporary workaround, consider restricting access to the file system to minimize the risk of exploitation.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Cloud Foundry
Pivotal Cloud Foundry (Pcf) Elastic Runtime