First published: Thu Dec 19 2019(Updated: )
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Credit: security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Capi-release | =1.88.0 | |
Cloudfoundry Cf-deployment | <12.7.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11294 refers to a vulnerability in Cloud Foundry Cloud Controller API (CAPI) version 1.88.0.
The severity of CVE-2019-11294 is medium with a CVSS score of 4.3.
Cloud Foundry Cloud Controller API (CAPI) version 1.88.0 and Cloudfoundry Cf-deployment versions up to 12.7.0 are affected by CVE-2019-11294.
Space developers can exploit CVE-2019-11294 to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
A fix for CVE-2019-11294 may be available through a software update provided by Cloud Foundry.