PT-2017-13437 · Cloud Foundry · Cf-Deployment+3
Published
2017-11-28
·
Updated
2021-05-25
·
CVE-2017-14389
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
capi-release versions prior to 1.45.0
cf-release versions prior to v280
cf-deployment versions prior to v1.0.0
Description
An issue allows space developers to create subdomains to an already existing route that belongs to a different user in a different org and space, also known as an "Application Subdomain Takeover." This occurs because the Cloud Controller does not prevent such actions.
Recommendations
For capi-release versions prior to 1.45.0, update to version 1.45.0 or later.
For cf-release versions prior to v280, update to version v280 or later.
For cf-deployment versions prior to v1.0.0, update to version v1.0.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Controller
Capi-Release
Cf-Deployment
Cf-Release