Security Advisory

CVE-2017-8038

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2017-11-27 10:00:00
Last updated 2024-08-05 16:19:29
Assigner dell
CVSS score not scored
State PUBLISHED

Description

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.