CVE-2018-11084: Garden-runC prevents deletion of some app environments
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-11084?
CVE-2018-11084 is a vulnerability in Cloud Foundry Garden-runC release versions prior to 1.16.1.
How does CVE-2018-11084 impact Cloud Foundry Garden-runC?
CVE-2018-11084 prevents deletion of some app environments based on file attributes, which can cause a denial of service for new app instances or scaling up of existing apps.
What is the severity of CVE-2018-11084?
CVE-2018-11084 has a severity rating of medium (6.5).
How can I fix CVE-2018-11084 in Cloud Foundry Garden-runC?
To fix CVE-2018-11084, upgrade Cloud Foundry Garden-runC to version 1.16.1 or higher.
Where can I find more information about CVE-2018-11084?
You can find more information about CVE-2018-11084 at the following link: [CVE-2018-11084](https://www.cloudfoundry.org/blog/cve-2018-11084/)