CVE-2018-1191: Infoleak
Published Mar 29, 2018
·Updated
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
Affected Software
2 affected components
Cloudfoundry Cf-deployment<1.9.0
Cloudfoundry Garden-runc-release<1.11.0
Event History
Mar 29, 2018
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
DescriptionWeakness
Frequently Asked Questions
1
What is CVE-2018-1191?
CVE-2018-1191 is an information exposure vulnerability in Cloud Foundry Garden-runC versions prior to 1.11.0.
2
How severe is CVE-2018-1191?
CVE-2018-1191 has a severity rating of 8.8 (High).
3
What is the affected software of CVE-2018-1191?
The affected software of CVE-2018-1191 is Cloud Foundry Garden-runC versions prior to 1.11.0.
4
What are the potential consequences of CVE-2018-1191?
The potential consequences of CVE-2018-1191 include leaked credentials and the ability to perform authenticated actions.
5
How can I fix CVE-2018-1191?
To fix CVE-2018-1191, upgrade to Cloud Foundry Garden-runC version 1.11.0 or later.