Description
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover."
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-5892 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover." |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/cve-2017-14389/ |
|
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-08-05T19:27:40.603Z
Reserved: 2017-09-12T00:00:00.000Z
Link: CVE-2017-14389
No data.
Status : Modified
Published: 2017-11-28T07:29:00.303
Modified: 2026-05-13T00:24:29.033
Link: CVE-2017-14389
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD