PT-2019-16715 · Cloud Foundry · Cloud Foundry Cloud Controller

Published

2019-03-13

·

Updated

2021-08-17

·

CVE-2019-3785

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry Cloud Controller versions prior to 1.78.0
Description The issue concerns an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
Recommendations For versions prior to 1.78.0, update to version 1.78.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the affected endpoint to minimize the risk of exploitation.

Fix

Improper Authorization

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3785

Affected Products

Cloud Foundry Cloud Controller