CVE-2019-3785
capi-release: Improper Authorization (CVE-2019-3785)
highEPSS 1.3%
Description
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
Metrics
Severity
high
73.25
no public PoC known
6.5
Published
2019-03-13 22:00 UTC
CWE-285
Weakness classes (CWE)
CWE-285Class
Improper Authorization
The product does not perform or incorrectly performs an authorization check when an actor attempts to access a resource or perform an action.
cwe.mitre.org →
Affected products
Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.
cloudfoundry
capi-release1.78.0
References & sources
IDCVE-2019-3785