CVE-2016-4435: BOSH Agent Anonymous Endpoint

23 views
Skip to first unread message

Chip Childers

unread,
Jun 13, 2016, 12:03:55 PM6/13/16
to BOSH Developers

CVE-2016-4435: BOSH Agent Anonymous Endpoint


Severity

Medium

Vendor

Cloud Foundry Foundation

Versions Affected

  • BOSH stemcell versions prior to 3232.6 and 3146.13.

Description

An endpoint of the Agent running on the BOSH Director VM may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.

Mitigation

Users are strongly encouraged to follow the mitigation below:

  • Upgrade BOSH stemcells to 3232.6 and 3146.13 or later.

Credit

This issue was identified by a Pivotal team and reported responsibly to the Cloud Foundry Foundation.

References



Reply all
Reply to author
Forward
0 new messages