Back

HIGH

Volume Services is vulnerable to an LDAP injection attack

Published Sep 23, 2019

Description

Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.

Affected products

Remediation

No remediation recorded yet.

Metrics

Weaknesses (2)

References (1)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner pivotal
Published Sep 23, 2019
Updated Sep 16, 2024
Reserved Apr 18, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a