PT-2017-13437 · Cloud Foundry · Cf-Deployment+3

Published

2017-11-28

·

Updated

2021-05-25

·

CVE-2017-14389

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions capi-release versions prior to 1.45.0 cf-release versions prior to v280 cf-deployment versions prior to v1.0.0
Description An issue allows space developers to create subdomains to an already existing route that belongs to a different user in a different org and space, also known as an "Application Subdomain Takeover." This occurs because the Cloud Controller does not prevent such actions.
Recommendations For capi-release versions prior to 1.45.0, update to version 1.45.0 or later. For cf-release versions prior to v280, update to version v280 or later. For cf-deployment versions prior to v1.0.0, update to version v1.0.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-14389

Affected Products

Cloud Controller
Capi-Release
Cf-Deployment
Cf-Release