ZeroHour

CVE-2018-1231

CVSS 3.0
8.8 high
EPSS
<1%p60
Published
()
Modified
Description

Cloud Foundry BOSH CLI, versions prior to v3.0.1, contains an improper access control vulnerability. A user with access to an instance using the BOSH CLI can access the BOSH CLI configuration file and use its contents to perform authenticated requests to BOSH.

Vendors
pivotal software
Products
bosh cli
Weakness
CWE-732
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.