PT-2019-12234 · Cloud Foundry · Cloud Foundry Cloud Controller
Publicado
2019-12-19
·
Atualizado
2021-08-17
·
CVE-2019-11294
CVSS v3.1
4.3
Média
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller API (CAPI) version 1.88.0
Description
The issue allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Recommendations
For Cloud Foundry Cloud Controller API (CAPI) version 1.88.0, restrict access to the global service brokers to minimize the risk of exploitation. As a temporary workaround, consider disabling the functionality that allows space developers to list global service brokers until a patch is available.
Correção
Incorrect Authorization
Information Disclosure
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Cloud Foundry Cloud Controller