CVE-2018-1265 in Pivotal Software and Cloudfoundry Products
Published on June 6, 2018
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.
Products Associated with CVE-2018-1265
You can be notified by email with stack.watch whenever vulnerabilities like CVE-2018-1265 are published in these products:
Affected Versions
Cloud Foundry Diego:- Version unspecified and below 2.8.0 is affected.
Exploit Probability
EPSS
0.65%
Percentile
70.41%
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.