CVE-2016-6658
29.03.2018, 22:29
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | cf-release | 𝑥 < 245 |
pivotal_software | cloud_foundry_elastic_runtime | 𝑥 < 1.6.49 |
pivotal_software | cloud_foundry_elastic_runtime | 1.7.0 ≤ 𝑥 < 1.7.31 |
pivotal_software | cloud_foundry_elastic_runtime | 1.8.0 ≤ 𝑥 < 1.8.11 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration