CVE-2023-20881 - CVE House
Back to Database
Status published Unknown CVE-2023-20881

Cloud foundry instances having CAPI version between 1.140 and 1.152.0...

Vulnerability Description

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-20881

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cloud Controller API
Vulnerable Versions:
Cloud Foundry cloud controller API versions between 1.140 and 1.152.0 and loggregator-agent v7+

Timeline

Official Publish: May 19th, 2023
Last Modified: January 21st, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)