CVE-2016-8219
medium
CVSS v3
6.5
CVSS v2
4.0
VIR risk
6.5
Description
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause application downtime if the restage fails.
Predictions
Exploit likelihood
75%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: security_alert@emc.com — https://www.cloudfoundry.org/cve-2016-8219/
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| cloudfoundry | capi-release | {"endExcluding":"1.12.0"} | 1.12.0 |
| cloudfoundry | cf-release | {"endExcluding":"250"} | 250 |
References
CWEs
CWE-269
Verify integrity in audit chain (admin only). AS-IS.