CVE-2018-15800

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
10/12/2018
Last modified:
09/10/2019

Description

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloud_foundry:bits_service:*:*:*:*:*:*:*:* 2.18.0 (excluding)


References to Advisories, Solutions, and Tools