CVE-2018-1266: Path Traversal
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on the Cloud Controller instance.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1266?
The severity of CVE-2018-1266 is high with a CVSS score of 8.1.
What is the vulnerability in Cloud Foundry Cloud Controller versions prior to 1.52.0?
The vulnerability in Cloud Foundry Cloud Controller versions prior to 1.52.0 is an information disclosure and path traversal vulnerability.
How can an authenticated malicious user exploit CVE-2018-1266?
An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that can overwrite files.
Which software versions are affected by CVE-2018-1266?
Cloud Foundry Cloud Controller versions prior to 1.52.0 are affected by CVE-2018-1266.
Where can I find more information about CVE-2018-1266?
You can find more information about CVE-2018-1266 on the Cloud Foundry website.