CVE-2018-15755: CF networking internal policy server SQL injection
Severity
Medium
Vendor
Cloud Foundry Foundation
Affected Cloud Foundry Products and Versions
- You are using cf-networking-release versions prior to 2.16.0
Description
Cloud Foundry CF-Networking, versions 2.11.0 through 2.15.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.
Mitigation
Users of affected versions should apply the following mitigations or upgrades:
- Releases that have fixed this issue include:
- cf-networking-release versions 2.16.0
History
2018-10-02: Initial vulnerability report published.