← Back

CVE-2023-20881

nvd nist
Published: May 19, 2023Modified: Jan 21, 2025

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.

Affected (3)

3 products
Capi Release
Cf Deployment
Loggregator Agent
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
From 1.140 to 1.152.0
From 24.7.0 to 29.0.0
From 7.0 to 7.2.1

Timeline

No history available yet.