CVE-2017-14388: Input Validation
Cloud Foundry Foundation GrootFS release 0.3.x versions prior to 0.30.0 do not validate DiffIDs, allowing specially crafted images to poison the grootfs volume cache. For example, this could allow an attacker to provide an image layer that GrootFS would consider to be the Ubuntu base layer.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14388?
The severity of CVE-2017-14388 is classified as medium due to potential risks of cache poisoning in the GrootFS volume.
How do I fix CVE-2017-14388?
To fix CVE-2017-14388, upgrade GrootFS to version 0.30.0 or later, which includes the necessary validation for DiffIDs.
What versions are affected by CVE-2017-14388?
CVE-2017-14388 affects all GrootFS versions prior to 0.30.0, including versions 0.3.0 to 0.29.0.
What impact does CVE-2017-14388 have on system integrity?
CVE-2017-14388 could lead to an attacker providing malicious image layers that compromise the integrity of the GrootFS cache.
Is there a workaround for CVE-2017-14388?
There is no known effective workaround for CVE-2017-14388; upgrading to the fixed version is the recommended approach.