CyberSec.Space Logo
返回 CVE 浏览器

CVE-2017-8038

HIGH
8.8
CVSS Severity Score
EPSS Score0.1540%
EPSS Percentile28.86th
Published2017年11月27日
Last Modified2026年5月13日

Vulnerability Description

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.

Affected Platforms (CPE)

📦
Pivotal Software

Credhub Release

= 1.1.0

References & Advisories

相关漏洞威胁