← Back to CVE List

CVE-2019-3785

Published: 2019-03-13T21:29Z
Last Modified: 2024-11-21T04:42Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt