First published: Thu May 25 2017(Updated: )
An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Bosh Stemcell | <=3232.4 | |
Pivotal Bosh Stemcell | =3146.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4435 has a high severity due to the potential for unauthenticated access and denial of service on the BOSH Director VM.
To fix CVE-2016-4435, upgrade to BOSH stemcell version 3232.6 or later and version 3146.14 or later.
CVE-2016-4435 affects Pivotal Bosh Stemcell versions prior to 3232.6 and version 3146.13.
Yes, CVE-2016-4435 may allow unauthenticated clients to read or write blobs, potentially exposing sensitive data.
CVE-2016-4435 is considered a remote vulnerability, as it can be exploited by unauthenticated clients over the network.