CVE-2018-1231
Last modified
CVE-2018-1231 is a vulnerability of currently unknown severity. Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.. EPSS estimates a 1.00% chance of exploitation in the next 30 days.
Description
Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Bosh Cli | < 3.0.1 |
References
- https://www.cloudfoundry.org/blog/cve-2018-1231/Third Party Advisory
- https://www.cloudfoundry.org/blog/cve-2018-1231/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-1231?
How severe is CVE-2018-1231?
How do I fix CVE-2018-1231?
Are you affected by CVE-2018-1231?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
