Cloud Controller provides signed URL with write authorization to read only user
Vulnerability Description
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-3785
Credits & Attribution
No credits recorded in the NVD database.
More from Cloud Foundry
View All →Affected Vendor
Cloud Foundry
View all reports →