Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2018-11-09T22:00:00Z

Updated: 2024-09-16T19:09:08.154Z

Reserved: 2018-08-23T00:00:00

Link: CVE-2018-15796

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-11-09T22:29:00.187

Modified: 2020-08-24T17:37:01.140

Link: CVE-2018-15796

cve-icon Redhat

No data.