Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
2020-09-03T01:15:10.763
2024-11-21T05:34:07.967
Modified
CVSSv3.1: 4.3 (MEDIUM)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | capi-release | < 1.98.0 | Yes |
Application | cloudfoundry | cf-deployment | < 13.17.0 | Yes |