CVE-2016-0708 is a medium-severity information disclosure vulnerability affecting Cloud Foundry applications deployed with specific versions (v166-v227) and using the Java Buildpack with automatic detection. This flaw allows remote attackers to access sensitive data like environment variables and bound service details if the application serves static content from its deployed artifact, particularly with default Apache Tomcat configurations for WAR files. The vulnerability has a CVSS score of 5.9 (MEDIUM) due to its high confidentiality impact and low attack complexity, though it requires specific conditions to be met. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 166, <= 227CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* | ||
>= 2.0, <= 3.4CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:java_buildpack:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.