HIGH🇵🇱 Wersja polska

CVE-2023-20881

CVSS 8.1v3.1pub. 2023-05-19upd. 2025-01-21

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
  • Cloudfoundry Capi Release

    APP
    Cloudfoundry
    1.140 – 1.152.0
  • Cloudfoundry Cf Deployment

    APP
    Cloudfoundry
    24.7.0 – 29.0.0
  • Cloudfoundry Loggregator Agent

    APP
    Cloudfoundry
    7.0 – 7.2.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2022-31733CRITICAL9.1PL ✓same product

Cloudfoundry Diego — pominięcie uwierzytelniania mTLS przez niezabezpieczony port

CVE-2019-3801CRITICAL9.8PL ✓same product

Cloud Foundry cf-deployment: wstrzyknięcie kodu przez niezaszyfrowany protokół pobierania zależności

CVE-2021-22101HIGH7.5same product

Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerabil...

CVE-2021-22001HIGH7.5same product

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in re...

CVE-2020-5423HIGH7.5same product

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an una...