Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2019-03-13T22:00:00Z

Updated: 2024-09-17T01:56:39.503Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Analyzed

Published: 2019-03-13T21:29:00.493

Modified: 2021-08-17T15:30:28.890

Link: CVE-2019-3785

cve-icon Redhat

No data.