Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: dell
Published: 2019-03-13T22:00:00Z
Updated: 2024-09-17T01:56:39.503Z
Reserved: 2019-01-03T00:00:00
Link: CVE-2019-3785
Vulnrichment
No data.
NVD
Status : Modified
Published: 2019-03-13T21:29:00.493
Modified: 2024-11-21T04:42:32.303
Link: CVE-2019-3785
Redhat
No data.