CVE Vulnerabilities

CVE-2017-8048

Published: Oct 04, 2017 | Modified: Aug 10, 2021
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
6.8 MEDIUM
AV:N/AC:M/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

Affected Software

Name Vendor Start Version End Version
Cf-release Cloudfoundry 268 (including) 268 (including)
Cf-release Cloudfoundry 269 (including) 269 (including)
Cf-release Cloudfoundry 270 (including) 270 (including)
Cf-release Cloudfoundry 271 (including) 271 (including)
Cf-release Cloudfoundry 272 (including) 272 (including)
Cf-release Cloudfoundry 273 (including) 273 (including)
Capi-release Pivotal 1.33.0 (including) 1.33.0 (including)
Capi-release Pivotal 1.34.0 (including) 1.34.0 (including)
Capi-release Pivotal 1.35.0 (including) 1.35.0 (including)
Capi-release Pivotal 1.36.0 (including) 1.36.0 (including)
Capi-release Pivotal 1.37.0 (including) 1.37.0 (including)
Capi-release Pivotal 1.38.0 (including) 1.38.0 (including)
Capi-release Pivotal 1.39.0 (including) 1.39.0 (including)
Capi-release Pivotal 1.40.0 (including) 1.40.0 (including)
Capi-release Pivotal 1.41.0 (including) 1.41.0 (including)

References