CVE-2017-8048 is a high-severity API regression in Cloud Foundry capi-release (versions 1.33.0 to 1.41.x) and cf-release (versions 268 to 273) that allows a space developer to execute arbitrary code on the Cloud Controller VM. This vulnerability, with a CVSS score of 7.8, arises from a flawed fix for a previous CVE, enabling remote code execution with high impact on confidentiality, integrity, and availability. While no active exploitation, public exploit code, or significant community discussion has been observed, the potential for a malicious developer to compromise the Cloud Controller VM remains a serious concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
268CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:268:*:*:*:*:*:*:* | ||
269CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:269:*:*:*:*:*:*:* | ||
270CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:270:*:*:*:*:*:*:* | ||
271CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:271:*:*:*:*:*:*:* | ||
272CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:272:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.