Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published: 2019-03-13T22:00:00Z

Updated: 2024-09-17T01:56:39.503Z

Reserved: 2019-01-03T00:00:00

Link: CVE-2019-3785

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2019-03-13T21:29:00.493

Modified: 2024-11-21T04:42:32.303

Link: CVE-2019-3785

cve-icon Redhat

No data.