CVE-2017-8033: Cloud Controller API filesystem traversal vulnerability
Severity
High
Vendor
Cloud Foundry Foundation
Versions Affected
- CAPI-release versions prior to v1.35.0
- cf-release versions prior to v268
Description
A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially-crafted application that can write arbitrary files to the Cloud Controller VM.
Mitigation
Users of affected versions should apply the following mitigation or upgrade:
- Upgrade to Cloud Foundry v268 [1] or later
- For standalone component users:
- Upgrade to CAPI-release 1.35.0 or later [2]
Credit
This vulnerability was responsibly reported by the GE Digital Security Team.
References
- [1] https://github.com/cloudfoundry/cf-release/releases
- [2] https://github.com/cloudfoundry/capi-release/releases
History
2017-07-19: Initial vulnerability report published