PT-2017-16233 · Cloud Foundry Foundation · Cf-Release+1

Published

2017-06-13

·

Updated

2019-10-03

·

CVE-2017-4970

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry Foundation cf-release version 255 Staticfile buildpack versions 1.4.0 through 1.4.3
Description An issue was discovered that causes the Staticfile.auth configuration to be ignored when the Static file is not present in the application root. This affects applications containing a Staticfile.auth file but not a Static file, resulting in basic auth being turned off when the Static file build pack is upgraded to a vulnerable version.
Recommendations For Cloud Foundry Foundation cf-release version 255, update the configuration to ensure proper detection of Staticfile.auth. For Staticfile buildpack versions 1.4.0 through 1.4.3, consider explicitly specifying the Static file build pack to prevent misconfiguration. As a temporary workaround, consider verifying the presence of the Static file in the application root to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2017-4970

Affected Products

Staticfile Buildpack
Cf-Release