Vulnerabilities
Vulnerable Software
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.
CVSS Score
7.2
EPSS Score
0.007
Published
2018-06-06


Contact Us

Shodan ® - All rights reserved