CVE-2015-5350 describes a high-severity vulnerability in Garden versions 0.22.0-0.329.0, specifically impacting Cloud Foundry deployments using Diego and Garden. An attacker could exploit a flaw in the garden-linux nstar executable by staging an application with a malicious custom buildpack. This allows unauthorized reading of host system files accessible to the BOSH-created vcap user, which can then be packaged into the application droplet. The CVSS score of 7.5 indicates a high-impact vulnerability with no authentication or user interaction required. There is no known exploit code publicly available, nor is there evidence of active exploitation, significant community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.330.0CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:garden:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.