CVE-2024-38826 Information
Nov 13, 2024
cve
Description
Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller.
The Cloud Foundry project recommends upgrading the following releases:
Upgrade capi release version to 1.194.0 or greater
Upgrade cf-deployment version to v44.1.0 or greater. This includes a patched capi release
Reference
https://www.cloudfoundry.org/blog/cve-2024-38826-cloud-controller-denial-of-service-attack/
Share on: