Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote…
dell·NVD-CWE-noinfo·Published 2018-09-18
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
Cloud Foundry Garden-runC release, en versiones anteriores a la 1.16.1, evita la eliminación de algunos entornos de aplicación basados en atributos de archivo. Un usuario autenticado remoto malicioso podría crear y eliminar aplicaciones con atributos de archivo manipulados para provocar una denegación de servicio (DoS) para nuevas instancias de la aplicación o para escalar aplicaciones existentes.
| Version | Type | Source | Base | Exp | Impact | Vector |
|---|---|---|---|---|---|---|
| 2.0 | Primary | NVD | 5.5 | 8.0 | 4.9 | AV:N/AC:L/Au:S/C:N/I:P/A:P |
| 3.0 | Primary | cve.org | 6.8 | — | — | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H |
| 3.0 | Primary | cve.org | 6.8 | — | — | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H |
| 3.0 | Primary | NVD | 6.5 | 2.8 | 3.6 | CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N |
| 3.0 | Secondary | NVD | 6.8 | 2.3 | 4.0 | CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:N/I:N/A:H |