PT-2018-13215 · Cloud Foundry · Cloud Foundry Bits Service

Christopher Brown

·

Published

2018-12-10

·

Updated

2019-10-09

·

CVE-2018-15800

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Cloud Foundry Bits Service versions prior to 2.18.0
Description The issue allows a remote malicious user to execute a timing attack, potentially brute-forcing the signing key. This could grant the attacker complete read and write access to the Bits Service storage.
Recommendations For versions prior to 2.18.0, update to version 2.18.0 or later to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-15800

Affected Products

Cloud Foundry Bits Service