CVE-2016-6639: High severity Cloudfoundry Php-buildpack vulnerability
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-6639?
CVE-2016-6639 is classified as a medium severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2016-6639?
To fix CVE-2016-6639, upgrade the Cloud Foundry PHP Buildpack to version 4.3.18 or later and the Pivotal Cloud Foundry Elastic Runtime to version 1.6.38 or later.
Who is affected by CVE-2016-6639?
CVE-2016-6639 affects users of Cloud Foundry PHP Buildpack versions prior to 4.3.18 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.6.38.
What type of vulnerability is CVE-2016-6639?
CVE-2016-6639 is a configuration vulnerability that allows the placement of sensitive files in publicly accessible directories.
When was CVE-2016-6639 published?
CVE-2016-6639 was published on September 22, 2016.