Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-0780


It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attacker could use an improper disk quota value to bypass enforcement and consume all the disk on DEAs/CELLs causing a potential denial of service for other applications.


Published

2017-05-25T17:29:00.520

Last Modified

2025-04-20T01:37:25.860

Status

Deferred

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-399

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cloudfoundry cf-release 231 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.0 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.1 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.2 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.3 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.4 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.5 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.6 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.7 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.8 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.9 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.10 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.11 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.12 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.13 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.14 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.15 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.5.16 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.0 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.1 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.2 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.3 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.4 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.5 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.6 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.7 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.8 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.9 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.10 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.11 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.12 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.13 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.14 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.15 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.16 Yes
Application pivotal_software cloud_foundry_elastic_runtime 1.6.17 Yes

References