PT-2018-11315 · Cloud Foundry · Cloud Foundry Cloud Controller
Publicado
2018-03-27
·
Atualizado
2021-09-09
·
CVE-2018-1266
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller versions prior to 1.52.0
Description
The issue allows an authenticated malicious user to predict the location of application blobs and leverage path traversal to create a malicious application. This malicious application has the ability to overwrite arbitrary files on the Cloud Controller instance.
Recommendations
For versions prior to 1.52.0, update to version 1.52.0 or later to resolve the issue.
Correção
Use of Insufficiently Random Values
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cloud Foundry Cloud Controller