First published: Thu Feb 22 2018(Updated: )
In Windows Stemcells versions prior to 1200.14, apps running inside containers in Windows on Google Cloud Platform are able to access the metadata endpoint. A malicious developer could use this access to gain privileged credentials.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Windows Stemcells | <1200.14 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1197 has a high severity rating due to the potential for unauthorized access to privileged credentials.
To fix CVE-2018-1197, upgrade to Windows Stemcells version 1200.14 or later.
CVE-2018-1197 affects apps running in containers on Windows within the Google Cloud Platform environment.
Developers using vulnerable versions of Windows Stemcells on Google Cloud Platform are at risk from CVE-2018-1197.
A malicious developer could exploit CVE-2018-1197 to access sensitive metadata and gain privileged credentials.