PT-2018-4400 · Cloud Foundry · Garden+2

Published

2018-03-19

·

Updated

2018-04-18

·

CVE-2015-5350

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Garden versions 0.22.0 through 0.329.0
Description A vulnerability has been discovered in the garden-linux nstar executable of Garden, allowing access to files on the host system. This issue can be exploited by staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack, enabling an end user to read files on the host system that the BOSH-created vcap user has permissions to read, and then package them into their app droplet.
Recommendations For Garden versions 0.22.0 through 0.329.0, consider restricting access to the garden-linux nstar executable until a patch is available. As a temporary workaround, avoid using custom buildpacks that could potentially exploit this issue.

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2015-5350

Affected Products

Bosh
Diego
Garden