Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
2019-03-13T21:29:00.493
2024-11-21T04:42:32.303
Modified
CVSSv3.1: 8.1 (HIGH)
AV:N/AC:L/Au:S/C:N/I:P/A:P
8.0
4.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | capi-release | < 1.78.0 | Yes |