Vulnerability Name:

CVE-2016-2169 (CCN-142525)

Assigned:2016-03-23
Published:2016-03-23
Updated:2018-05-24
Summary:Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service.
CVSS v3 Severity:5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
4.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N)
3.8 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
4.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-17
Vulnerability Consequences:Gain Access
References:Source: MITRE
Type: CNA
CVE-2016-2169

Source: XF
Type: UNKNOWN
cloudfoundry-cve20162169-weak-security(142525)

Source: CCN
Type: cloudfoundry GIT Repository
CAPI shouldn't allow users to create apps with routes matching CF service subdomains #568

Source: CONFIRM
Type: Third Party Advisory
https://github.com/cloudfoundry/cloud_controller_ng/issues/568

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cloudfoundry:capi-release:*:*:*:*:*:*:*:* (Version < 1.0.0)
  • AND
  • cpe:/h:cloudfoundry:cloud_controller:-:*:*:*:*:*:*:*

  • Configuration 2:
  • cpe:/a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* (Version < 237)
  • AND
  • cpe:/h:cloudfoundry:cloud_controller:-:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:cloud_foundry:cf-release:231:*:*:*:*:*:*:*
  • OR cpe:/a:cloud_foundry:capi-release:1.11.0:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cloudfoundry capi-release *
    cloudfoundry cloud controller -
    cloudfoundry cf-release *
    cloudfoundry cloud controller -
    cloud_foundry cf-release 231
    cloud_foundry capi-release 1.11.0