CVE-2019-11277: Volume Services is vulnerable to an LDAP injection attack
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-11277.
What is the severity level of CVE-2019-11277?
CVE-2019-11277 has a severity level of high.
Which versions of Cloud Foundry NFS Volume Service are affected by CVE-2019-11277?
Versions 1.7.x (prior to 1.7.11) and 2.x (prior to 2.3.0) of Cloud Foundry NFS Volume Service are affected by CVE-2019-11277.
How can a remote authenticated malicious space developer exploit CVE-2019-11277?
A remote authenticated malicious space developer can exploit CVE-2019-11277 by injecting LDAP filters via service instance creation, potentially leading to denial of service.
Where can I find more information about CVE-2019-11277?
More information about CVE-2019-11277 can be found at https://www.cloudfoundry.org/blog/cve-2019-11277.