Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
BID:100448
CVE-2017-8037 |Info
Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
| Bugtraq ID: | 100448 |
| Class: | Input Validation Error |
| CVE: |
CVE-2017-8037 |
| Remote: | Yes |
| Local: | No |
| Published: | Aug 07 2017 12:00AM |
| Updated: | Mar 22 2019 07:00AM |
| Credit: | GE Digital Security Team. |
| Vulnerable: |
Cloud Foundry cf-release 269 Cloud Foundry cf-release 268 Cloud Foundry cf-release 267 Cloud Foundry cf-release 260 Cloud Foundry cf-release 250 Cloud Foundry cf-release 245 Cloud Foundry capi-release 1.37 Cloud Foundry capi-release 1.36 Cloud Foundry capi-release 1.35 Cloud Foundry capi-release 1.34 Cloud Foundry capi-release 1.33 Cloud Foundry capi-release 1.30 Cloud Foundry capi-release 1.20 Cloud Foundry capi-release 1.12 Cloud Foundry capi-release 1.10 Cloud Foundry capi-release 1.7 Cloud Foundry CAPI 1.37 Cloud Foundry CAPI 1.30 Cloud Foundry CAPI 1.20 Cloud Foundry CAPI 1.15 Cloud Foundry CAPI 1.10 Cloud Foundry CAPI 1.6 |
| Not Vulnerable: |
Cloud Foundry cf-release 270 Cloud Foundry capi-release 1.38 Cloud Foundry CAPI 1.38 |
Discussion
Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
Cloud Foundry Cloud Controller API is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
CAPI-release 1.7.0 through 1.37.0 and cf-release 245 through 269 are vulnerable.
Cloud Foundry Cloud Controller API is prone to an information-disclosure vulnerability.
An attacker can exploit this issue to gain access to sensitive information that may aid in further attacks.
CAPI-release 1.7.0 through 1.37.0 and cf-release 245 through 269 are vulnerable.
Exploit / POC
Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution / Fix
Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Cloud Foundry Cloud Controller API CVE-2017-8037 Incomplete Fix Information Disclosure Vulnerability
References:
References:
- Cloud Foundry capi-release (Cloud Foundry)
- Cloud Foundry Homepage (Cloud Foundry Foundation)
- cloudfoundry/cf-release (Cloud Foundry)
- CVE-2017-8035: Cloud Controller API access to CC VM contents (Cloud Foundry)