PT-2017-8487 · Bosh · Bosh Director Vm Stemcell
Publicado
2017-05-25
·
Atualizado
2017-10-02
·
CVE-2016-4435
CVSS v3.1
9.0
Crítica
| Vetor | AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
BOSH Director VM stemcell versions prior to 3232.6
BOSH Director VM stemcell versions prior to 3146.13
Description
The issue allows unauthenticated clients to potentially read or write blobs or cause a denial of service attack on the Director VM by guessing or finding a URL matching an existing GUID, affecting an endpoint of the Agent running on the BOSH Director VM.
Recommendations
For stemcell versions prior to 3232.6, update to version 3232.6 or later to resolve the issue.
For stemcell versions prior to 3146.13, update to version 3146.13 or later to resolve the issue.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bosh Director Vm Stemcell