PT-2018-4400 · Cloud Foundry · Garden+2
Publicado
2018-03-19
·
Atualizado
2018-04-18
·
CVE-2015-5350
CVSS v2.0
5.0
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Garden versions 0.22.0 through 0.329.0
Description
A vulnerability has been discovered in the garden-linux nstar executable of Garden, allowing access to files on the host system. This issue can be exploited by staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack, enabling an end user to read files on the host system that the BOSH-created vcap user has permissions to read, and then package them into their app droplet.
Recommendations
For Garden versions 0.22.0 through 0.329.0, consider restricting access to the garden-linux nstar executable until a patch is available. As a temporary workaround, avoid using custom buildpacks that could potentially exploit this issue.
Correção
Improper Access Control
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Bosh
Diego
Garden