CVE-2017-8037: Infoleak
In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035 you should also upgrade to fix this CVE. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for that installation, aka an Information Leak / Disclosure.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8037?
CVE-2017-8037 has a moderate severity level, indicating it could potentially lead to unauthorized access or data exposure.
How do I fix CVE-2017-8037?
To remedy CVE-2017-8037, upgrade to Cloud Foundry CAPI-release versions 1.38.0 or newer, and cf-release versions 270 or newer.
Which versions are affected by CVE-2017-8037?
CVE-2017-8037 affects CAPI-release versions after v1.6.0 and before v1.38.0, as well as cf-release versions after v244 and before v270.
Is CVE-2017-8037 related to CVE-2017-8035?
Yes, CVE-2017-8037 represents an incomplete fix for the vulnerabilities identified in CVE-2017-8035.
What should I do if I have already remediated CVE-2017-8035?
If you have remediated CVE-2017-8035, you should also ensure to upgrade your versions to address CVE-2017-8037.