Total vulnerabilities in the database
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.
Software | From | Fixed in |
---|---|---|
cloudfoundry / cf-release | - | 245 |
pivotal_software / cloud_foundry_elastic_runtime | - | 1.6.49 |
pivotal_software / cloud_foundry_elastic_runtime | 1.7.0 | 1.7.31 |
pivotal_software / cloud_foundry_elastic_runtime | 1.8.0 | 1.8.11 |