CyberSec.Space Logo
Back to CVE Browser

CVE-2017-8038

HIGH
8.8
CVSS Severity Score
EPSS Score0.1540%
EPSS Percentile28.86th
PublishedNov 27, 2017
Last ModifiedMay 13, 2026

Vulnerability Description

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.

Affected Platforms (CPE)

📦
Pivotal Software

Credhub Release

= 1.1.0

References & Advisories

Related Vulnerabilities