CVE-2018-1231

Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.
References
Link Resource
https://www.cloudfoundry.org/blog/cve-2018-1231/ Third Party Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:pivotal_software:bosh_cli:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-03-27 16:29

Updated : 2023-12-10 12:30


NVD link : CVE-2018-1231

Mitre link : CVE-2018-1231

CVE.ORG link : CVE-2018-1231


JSON object : View

Products Affected

pivotal_software

  • bosh_cli
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource