Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-84j7-fm4m-279g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.

EPSS

Процентиль: 58%
0.0037
Низкий

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 8.1
nvd
почти 7 лет назад

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.

EPSS

Процентиль: 58%
0.0037
Низкий

Дефекты

CWE-269