CVE-2019-11294: CAPI leaks service broker URLs and GUIDs to space developers
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11294?
CVE-2019-11294 refers to a vulnerability in Cloud Foundry Cloud Controller API (CAPI) version 1.88.0.
What is the severity of CVE-2019-11294?
The severity of CVE-2019-11294 is medium with a CVSS score of 4.3.
What is affected by CVE-2019-11294?
Cloud Foundry Cloud Controller API (CAPI) version 1.88.0 and Cloudfoundry Cf-deployment versions up to 12.7.0 are affected by CVE-2019-11294.
How can space developers exploit CVE-2019-11294?
Space developers can exploit CVE-2019-11294 to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Is there a fix for CVE-2019-11294?
A fix for CVE-2019-11294 may be available through a software update provided by Cloud Foundry.