PT-2019-12234 · Cloud Foundry · Cloud Foundry Cloud Controller

Publicado

2019-12-19

·

Atualizado

2021-08-17

·

CVE-2019-11294

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry Cloud Controller API (CAPI) version 1.88.0
Description The issue allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Recommendations For Cloud Foundry Cloud Controller API (CAPI) version 1.88.0, restrict access to the global service brokers to minimize the risk of exploitation. As a temporary workaround, consider disabling the functionality that allows space developers to list global service brokers until a patch is available.

Correção

Incorrect Authorization

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11294

Produtos afetados

Cloud Foundry Cloud Controller