CVE-2017-8035: Cloud Controller API access to CC VM contents
Cloud Foundry Foundation
- CAPI-release versions after v1.6.0 and prior to v1.35.0
- cf-release versions after v244 and prior to v268
A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for that installation.
Users of affected versions should apply the following mitigation or upgrade:
- Upgrade to Cloud Foundry v268  or later
- For standalone component users:
- Upgrade to CAPI-release 1.35.0 or later 
This vulnerability was responsibly reported by the GE Digital Security Team.
-  https://github.com/cloudfoundry/cf-release/releases
-  https://github.com/cloudfoundry/capi-release/releases
2017-07-19: Initial vulnerability report published
2017-07-19: Update vulnerable CAPI and cf versions