Description
Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-7621 | Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2018-15755/ |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-17T00:31:36.023Z
Reserved: 2018-08-23T00:00:00.000Z
Link: CVE-2018-15755
No data.
Status : Modified
Published: 2018-10-12T22:15:07.237
Modified: 2024-11-21T03:51:24.510
Link: CVE-2018-15755
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD