Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1268


Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.


Published

2018-06-06T20:29:00.503

Last Modified

2024-11-21T03:59:30.240

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

6.8

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cloudfoundry loggregator < 89.5 Yes
Application cloudfoundry loggregator < 96.1 Yes
Application cloudfoundry loggregator < 99.1 Yes
Application cloudfoundry loggregator < 101.9 Yes
Application cloudfoundry loggregator < 102.2 Yes

References