CVE-2017-8048

UnknownEPSS 1.24%

Last modified

CVE-2017-8048 is a vulnerability of currently unknown severity. In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.. EPSS estimates a 1.24% chance of exploitation in the next 30 days.

Description

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

Metrics

EPSS Probability
1.24%

65.5th percentile

Probability of exploitation in the next 30 days. Learn more

Affected Software

VendorProductVersions
CloudfoundryCf-Release268
CloudfoundryCf-Release269
CloudfoundryCf-Release270
CloudfoundryCf-Release271
CloudfoundryCf-Release272
CloudfoundryCf-Release273
PivotalCapi-Release1.33.0
PivotalCapi-Release1.34.0
PivotalCapi-Release1.35.0
PivotalCapi-Release1.36.0
PivotalCapi-Release1.37.0
PivotalCapi-Release1.38.0
PivotalCapi-Release1.39.0
PivotalCapi-Release1.40.0
PivotalCapi-Release1.41.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-8048?
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.
How severe is CVE-2017-8048?
Severity scoring for CVE-2017-8048 is pending analysis. The EPSS model estimates a 1.24% probability of exploitation in the next 30 days.
How do I fix CVE-2017-8048?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-8048?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST