Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
2019-09-23T18:15:11.553
2024-11-21T04:20:50.260
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:P/I:N/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | cf-deployment | < 11.1.0 | Yes |
Application | cloudfoundry | nfs_volume_release | < 1.7.11 | Yes |
Application | cloudfoundry | nfs_volume_release | < 2.3.0 | Yes |