First published: Tue Mar 27 2018(Updated: )
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Bosh Cli | <3.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1231 is classified as a medium-severity vulnerability due to improper access control in the BOSH CLI.
To fix CVE-2018-1231, upgrade BOSH CLI to version 3.0.1 or later.
CVE-2018-1231 affects users of BOSH CLI versions prior to 3.0.1.
An attacker with access can view the BOSH CLI configuration file and conduct authenticated requests to the BOSH server.
CVE-2018-1231 was publicly disclosed in early 2018.