CVE-2017-4969: Medium severity cloudfoundry Cf-release vulnerability
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Cloud Foundry cf-release (Cloud Controller)to a version that resolves this vulnerability.Fixed in v255
Event History
Frequently Asked Questions
What is the severity of CVE-2017-4969?
CVE-2017-4969 is classified as a medium severity vulnerability due to its potential impact on resource management.
How do I fix CVE-2017-4969?
To mitigate CVE-2017-4969, upgrade your Cloud Foundry cf-release to version 255 or later.
What causes CVE-2017-4969?
CVE-2017-4969 is caused by the Cloud Controller not properly enforcing memory and disk quotas for authenticated developer users.
Who is impacted by CVE-2017-4969?
Authenticated developer users in Cloud Foundry cf-release versions prior to 255 are at risk of exceeding their allocated resources.
What is the potential impact of CVE-2017-4969?
The potential impact of CVE-2017-4969 includes unauthorized resource consumption which can lead to service degradation.