Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HCloudfoundry Garden Linux
APPCloudfoundry≤ 0.332.0Pivotal Software Cloud Foundry Elastic Runtime
APPPivotal Software1.6.01.6.11.6.101.6.111.6.121.6.131.6.141.6.151.6.161.6.21.6.31.6.41.6.51.6.61.6.7+ 2 more
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Container
CWE
Related vulnerabilities
CVE-2016-6658CRITICAL9.6PL ✓same product
Ujawnienie danych uwierzytelniających buildpack w Cloud Foundry CF-Release
CVE-2015-5172CRITICAL9.8PL ✓same product
Cloud Foundry: brak wygasania linków resetowania hasła
CVE-2015-5171CRITICAL9.8PL ✓same product
Cloud Foundry: brak unieważniania sesji po zmianie hasła
CVE-2017-2773CRITICAL9.8PL ✓same product
Pivotal PCF Elastic Runtime — podszywanie się pod użytkowników przez błąd walidacji JWT
CVE-2017-4955CRITICAL9.8PL ✓same product
Pivotal PCF Elastic Runtime — dane uwierzytelniające ujawnione w logach