An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted application that can write arbitrary files to the Cloud Controller VM.
Advisories
Source ID Title
EUVD EUVD EUVD-2017-17000 An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted application that can write arbitrary files to the Cloud Controller VM.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-05T16:19:29.592Z

Reserved: 2017-04-21T00:00:00

Link: CVE-2017-8033

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-07-25T04:29:00.227

Modified: 2025-04-20T01:37:25.860

Link: CVE-2017-8033

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.