CVE-2017-8036Capi-release vulnerability

3 documents3 sources
Severity
7.8HIGHNVD
EPSS
0.4%
top 36.35%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 24
Latest updateMay 13

Description

An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages1 packages

🔴Vulnerability Details

2
GHSA
GHSA-hp2f-4chh-4499: An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 12022-05-13
CVEList
CVE-2017-8036: An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 12017-07-24
CVE-2017-8036 — Cloudfoundry Capi-release vulnerability | cvebase