CVE-2018-1267 Information
Feb 14, 2021
cve
Description
Cloud Foundry Silk CNI plugin versions prior to 0.2.0 contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network any applications can reach any other application on the network regardless of the configured routing policies.
CVSS Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://www.cloudfoundry.org/blog/cve-2018-1267/
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
8.1
Share on: