CVE-2018-15755: CF networking internal policy server SQL injection
Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-15755?
CVE-2018-15755 is classified as a high severity vulnerability due to the potential for remote SQL injection by an authenticated user.
How do I fix CVE-2018-15755?
To mitigate CVE-2018-15755, upgrade to Cloud Foundry CF Networking Release version 2.16.0 or later.
What software is affected by CVE-2018-15755?
CVE-2018-15755 affects Cloud Foundry CF Networking versions from 2.11.0 to 2.15.0.
Who can exploit CVE-2018-15755?
A remote authenticated malicious user with mTLS certificates can exploit CVE-2018-15755 to issue arbitrary SQL queries.
What is the attack vector for CVE-2018-15755?
The attack vector for CVE-2018-15755 is an internal API endpoint vulnerable to SQL injection between Diego cells and the policy server.