All Vulnerability Reports

CVE-2018-11084: Garden-runC prevents deletion of some app environments


Severity

Medium

Vendor

Pivotal

Description

Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.

Affected Pivotal Products and Versions

Severity is medium unless otherwise noted.

  • Pivotal Application Service
    • 2.2.x versions prior to 2.2.7
    • 2.1.x versions prior to 2.1.15
  • Pivotal Application Service for Windows
    • 2.2.x versions prior to 2.2.4
    • 2.1.x versions prior to 2.1.10
  • PCF Isolation Segments
    • 2.2.x versions prior to 2.2.6
    • 2.1.x versions prior to 2.1.13
Mitigation

Users of affected versions should apply the following mitigation:

  • Releases that have fixed this issue include:
    • Pivotal Application Service: 2.2.7, 2.1.15
    • Pivotal Application Service for WIndows: 2.2.4, 2.1.10
    • PCF Isolation Segments: 2.2.6, 2.1.13
References
History

2018-08-10: Initial vulnerability report published.

2018-09-07: Updated CVE ID. Prior version referenced CVE-2018-11048, which is incorrect.