An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://pivotal.io/security/cve-2016-4435 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2017-05-25T17:00:00
Updated: 2024-08-06T00:32:24.614Z
Reserved: 2016-05-02T00:00:00
Link: CVE-2016-4435
Vulnrichment
No data.
NVD
Status : Modified
Published: 2017-05-25T17:29:00.677
Modified: 2024-11-21T02:52:11.303
Link: CVE-2016-4435
Redhat
No data.