CVE-2017-8048: High severity Cloudfoundry Cf-release vulnerability
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8048?
CVE-2017-8048 has a critical severity level due to the potential for arbitrary code execution on the Cloud Controller VM.
What versions are affected by CVE-2017-8048?
CVE-2017-8048 affects Cloud Foundry capi-release versions 1.33.0 to 1.41.0 and cf-release versions 268 to 273.
How do I fix CVE-2017-8048?
To fix CVE-2017-8048, upgrade to capi-release version 1.42.0 or later and cf-release version 274 or later.
What type of vulnerabilities does CVE-2017-8048 represent?
CVE-2017-8048 represents a security vulnerability that allows space developers to execute arbitrary code.
Can unauthorized users exploit CVE-2017-8048?
Yes, unauthorized users with space developer roles can exploit CVE-2017-8048 due to its design flaw.