PT-2019-12234 · Cloud Foundry · Cloud Foundry Cloud Controller
Published
2019-12-19
·
Updated
2021-08-17
·
CVE-2019-11294
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Cloud Controller API (CAPI) version 1.88.0
Description
The issue allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Recommendations
For Cloud Foundry Cloud Controller API (CAPI) version 1.88.0, restrict access to the global service brokers to minimize the risk of exploitation. As a temporary workaround, consider disabling the functionality that allows space developers to list global service brokers until a patch is available.
Fix
Incorrect Authorization
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Foundry Cloud Controller