CVE Vulnerabilities

CVE-2017-8048

Published: Oct 04, 2017 | Modified: Apr 20, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

Affected Software

NameVendorStart VersionEnd Version
Cf-releaseCloudfoundry268 (including)268 (including)
Cf-releaseCloudfoundry269 (including)269 (including)
Cf-releaseCloudfoundry270 (including)270 (including)
Cf-releaseCloudfoundry271 (including)271 (including)
Cf-releaseCloudfoundry272 (including)272 (including)
Cf-releaseCloudfoundry273 (including)273 (including)
Capi-releasePivotal1.33.0 (including)1.33.0 (including)
Capi-releasePivotal1.34.0 (including)1.34.0 (including)
Capi-releasePivotal1.35.0 (including)1.35.0 (including)
Capi-releasePivotal1.36.0 (including)1.36.0 (including)
Capi-releasePivotal1.37.0 (including)1.37.0 (including)
Capi-releasePivotal1.38.0 (including)1.38.0 (including)
Capi-releasePivotal1.39.0 (including)1.39.0 (including)
Capi-releasePivotal1.40.0 (including)1.40.0 (including)
Capi-releasePivotal1.41.0 (including)1.41.0 (including)

References