CVE Published: 27/11/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: dell |
Vendor: n/a |
Product: Credhub Credhub-release version 1.1.0 only Status : PUBLISHED
CVE-2017-8038 Description
In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.