Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2017-8033: Cloud Controller API filesystem traversal vulnerability

CVE-2017-8033: Cloud Controller API filesystem traversal vulnerability

Severity

High

Vendor

Cloud Foundry Foundation

Versions Affected

  • CAPI-release versions prior to v1.35.0
  • cf-release versions prior to v268

Description

A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially-crafted application that can write arbitrary files to the Cloud Controller VM.

Mitigation

Users of affected versions should apply the following mitigation or upgrade:

  • Upgrade to Cloud Foundry v268 [1] or later
  • For standalone component users:
    • Upgrade to CAPI-release 1.35.0 or later [2]

Credit

This vulnerability was responsibly reported by the GE Digital Security Team.

References

History

2017-07-19: Initial vulnerability report published

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES