PT-2019-12224 · Cloud Foundry · Cloud Foundry Nfs Volume Service

Publicado

2019-09-23

·

Atualizado

2019-10-09

·

CVE-2019-11277

CVSS v3.1

8.4

Alta

VetorAV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Cloud Foundry NFS Volume Service versions 1.7.x prior to 1.7.11 Cloud Foundry NFS Volume Service versions 2.x prior to 2.3.0
Description The issue allows a remote authenticated malicious space developer to potentially inject LDAP filters via service instance creation. This could facilitate the malicious space developer to deny service or perform a dictionary attack.
Recommendations For versions 1.7.x prior to 1.7.11, update to version 1.7.11 or later. For versions 2.x prior to 2.3.0, update to version 2.3.0 or later.

Correção

Special Elements Injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11277

Produtos afetados

Cloud Foundry Nfs Volume Service