Severity
High
Vendor
Cloud Foundry Foundation
Description
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
Affected Cloud Foundry Products and Versions
- CF Deployment
- All versions prior to v11.1.0
- CF NFS volume release
- 1.7 versions prior to v1.7.11
- 2.x versions prior to v2.3.0
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
- CF Deployment
- Upgrade All versions to v11.1.0 or greater
- CF NFS volume release
- Upgrade 1.7 versions to v1.7.11 or greater
- Upgrade 2.x versions to v2.3.0 or greater
History
2019-09-23: Initial vulnerability report published.