CVE-2018-1267: High severity Cloudfoundry Silk-release Cloudfoundry vulnerability
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured routing policies.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1267?
CVE-2018-1267 has a medium severity rating due to improper access control vulnerabilities.
How do I fix CVE-2018-1267?
To fix CVE-2018-1267, upgrade the Cloud Foundry Silk CNI plugin to version 0.2.0 or later.
What systems are affected by CVE-2018-1267?
CVE-2018-1267 affects Cloud Foundry Silk release versions prior to 0.2.0.
What type of vulnerability is CVE-2018-1267?
CVE-2018-1267 is classified as an improper access control vulnerability.
What are the implications of CVE-2018-1267?
The implications of CVE-2018-1267 allow applications to access each other on the network without appropriate restrictions.