CVE-2018-15755

Severity CVSS v4.0:
Pending analysis
Type:
CWE-89 SQL Injection
Publication date:
12/10/2018
Last modified:
09/10/2019

Description

Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloud_foundry:cf-networking:*:*:*:*:*:*:*:* 2.11.0 (including) 2.16.0 (excluding)


References to Advisories, Solutions, and Tools