← Back

CVE-2018-1268

nvd nist
Published: Jun 6, 2018Modified: Nov 21, 2024

JSON object

Loading...
6.8
Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 1.6 / Impact: 5.2
Source: NVD

Description

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.

Affected (5)

1 product
Loggregator
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Cloudfoundry
From 101 to 101.9
From 102 to 102.2
From 89 to 89.5
From 96 to 96.1
From 99 to 99.1

References (2)

Source: security_alert@emc.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.