PT-2018-4903 · Cloud Foundry · Cloud Foundry Cloud Controller
Djvdorpop
·
Published
2018-04-18
·
Updated
2018-05-24
·
CVE-2016-2169
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0
Cloud Foundry Cloud Controller, cf-release versions prior to v237
Description
The issue is related to a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route, potentially receiving traffic intended for the service.
Recommendations
For capi-release versions prior to 1.0.0, update to version 1.0.0 or later to resolve the issue.
For cf-release versions prior to v237, update to version v237 or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry Cloud Controller