First published: Thu May 17 2018(Updated: )
Windows 2012R2 stemcells, versions prior to 1200.17, contain an information exposure vulnerability on vSphere. A remote user with the ability to push apps can execute crafted commands to read the IaaS metadata from the VM, which may contain BOSH credentials.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Windows Stemcells | <1200.17 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1276 has a high severity rating due to the potential exposure of sensitive IaaS metadata and BOSH credentials.
To fix CVE-2018-1276, upgrade to Windows 2012R2 stemcells version 1200.17 or later.
Applications deployed in environments using Windows 2012R2 stemcells prior to version 1200.17 are vulnerable to CVE-2018-1276.
Organizations using Pivotal Software Windows Stemcells versions prior to 1200.17 are affected by CVE-2018-1276.
CVE-2018-1276 may expose IaaS metadata, which could include sensitive information such as BOSH credentials.