PT-2018-4400 · Cloud Foundry · Garden+2

Publicado

2018-03-19

·

Atualizado

2018-04-18

·

CVE-2015-5350

CVSS v2.0

5.0

Média

VetorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Garden versions 0.22.0 through 0.329.0
Description A vulnerability has been discovered in the garden-linux nstar executable of Garden, allowing access to files on the host system. This issue can be exploited by staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack, enabling an end user to read files on the host system that the BOSH-created vcap user has permissions to read, and then package them into their app droplet.
Recommendations For Garden versions 0.22.0 through 0.329.0, consider restricting access to the garden-linux nstar executable until a patch is available. As a temporary workaround, avoid using custom buildpacks that could potentially exploit this issue.

Correção

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-5350

Produtos afetados

Bosh
Diego
Garden