PT-2018-11315 · Cloud Foundry · Cloud Foundry Cloud Controller
Published
2018-03-27
·
Updated
2021-09-09
·
CVE-2018-1266
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller versions prior to 1.52.0
Description
The issue allows an authenticated malicious user to predict the location of application blobs and leverage path traversal to create a malicious application. This malicious application has the ability to overwrite arbitrary files on the Cloud Controller instance.
Recommendations
For versions prior to 1.52.0, update to version 1.52.0 or later to resolve the issue.
Fix
Use of Insufficiently Random Values
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Foundry Cloud Controller