CVE Database
/

CVE-2018-1265

Back to search

CVE-2018-1265

Published: Jun 6, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.

VendorProductVersions

Cloud Foundry

Diego

affected
unspecified - < 2.8.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now