CVE-2020-5418
03.09.2020, 01:15
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | capi-release | 𝑥 < 1.98.0 |
cloudfoundry | cf-deployment | 𝑥 < 13.17.0 |
𝑥
= Vulnerable software versions