VYPR

Cloud Foundry Diego

by Cloudfoundry

CVEs (1)

  • CVE-2018-1265HigJun 6, 2018
    risk 0.47cvss 7.2epss 0.02

    Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps…