PT-2018-4400 · Cloud Foundry · Garden+2
Published
2018-03-19
·
Updated
2018-04-18
·
CVE-2015-5350
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Garden versions 0.22.0 through 0.329.0
Description
A vulnerability has been discovered in the garden-linux nstar executable of Garden, allowing access to files on the host system. This issue can be exploited by staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack, enabling an end user to read files on the host system that the BOSH-created vcap user has permissions to read, and then package them into their app droplet.
Recommendations
For Garden versions 0.22.0 through 0.329.0, consider restricting access to the garden-linux nstar executable until a patch is available. As a temporary workaround, avoid using custom buildpacks that could potentially exploit this issue.
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bosh
Diego
Garden