CVE-2020-5418 LOW

CVE-2020-5418: Cloud Controller allows users with no roles to list droplets

Vendor Cloud Foundry
Product CAPI
Weakness CWE-863 · Incorrect authorization
Published September 3, 2020
Last update September 17, 2024

CVSS base score

3.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction None
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N

What the vulnerability does

01Description

Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).

Key dates

02Disclosure timeline

September 3, 2020 CVE published
September 17, 2024 Record updated