CVE-2017-8048

high
Published 2017-10-04 ยท Modified 2026-05-13
CVSS v3
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
7.8

Description

In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. NOTE: 274 resolves the vulnerability but has a serious bug that is fixed in 275.

Predictions

Exploit likelihood
75%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

No mitigations published for this CVE yet.

The vendor-content worker queues fetches as references arrive (check back in a few minutes). Or โ€” if you've already worked around this in production โ€” publish your fix to the community-verified tier.

โœš Propose a mitigation on Community โ†’ Mitigations published via the community go through AI scoring + 2 human reviewers + 7-day silent objection window before landing here with source_tier=community-verified.

Application impact

VendorProductVersionsFixed
cloudfoundrycf-release268
cloudfoundrycf-release269
cloudfoundrycf-release270
cloudfoundrycf-release271
cloudfoundrycf-release272
cloudfoundrycf-release273
pivotalcapi-release1.33.0
pivotalcapi-release1.34.0
pivotalcapi-release1.35.0
pivotalcapi-release1.36.0
pivotalcapi-release1.37.0
pivotalcapi-release1.38.0
pivotalcapi-release1.39.0
pivotalcapi-release1.40.0
pivotalcapi-release1.41.0

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.