CVE-2017-8037: Incomplete fix for Cloud Controller API access to CC VM Contents Severity Critical Vendor Cloud Foundry Foundation Versions Affected CAPI-release versions after v1.6.0 and prior to v1.38.0 cf-release versions after v244 and prior to v270 Description This CVE is for an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035, you should also upgrade to fix this CVE. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for that installation. Mitigation Users of affected versions should apply the following mitigation or upgrade: Upgrade to Cloud Foundry v270 [1] or later For standalone component users: - Upgrade to CAPI-release 1.38.0 or later [2] Credit This vulnerability was responsibly reported by the GE Digital Security Team. References [1] https://github.com/cloudfoundry/cf-release/releases [2] https://github.com/cloudfoundry/capi-release/releases History 2017-08-07: Initial vulnerability report published