Описание
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
Ссылки
- Third Party AdvisoryVDB Entry
- Vendor Advisory
- Third Party AdvisoryVDB Entry
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 7.9.0 (исключая)Версия от 1.9 (включая) до 1.9.10 (исключая)Версия от 2.1 (включая) до 2.1.3 (исключая)Версия до 64.0 (исключая)
Одно из
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:credhub:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*
EPSS
Процентиль: 47%
0.00588
Низкий
8.7 High
CVSS3
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-494
CWE-319
Связанные уязвимости
CVSS3: 9.8
github
больше 4 лет назад
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
EPSS
Процентиль: 47%
0.00588
Низкий
8.7 High
CVSS3
9.8 Critical
CVSS3
5 Medium
CVSS2
Дефекты
CWE-494
CWE-319