Vulnerability Description
In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locations.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Pivotal Software | Cf-Deployment | 0.35.0 |
References
- http://www.securityfocus.com/bid/101972Third Party AdvisoryVDB Entry
- https://www.cloudfoundry.org/cve-2017-14390/Issue TrackingThird Party Advisory
- http://www.securityfocus.com/bid/101972Third Party AdvisoryVDB Entry
- https://www.cloudfoundry.org/cve-2017-14390/Issue TrackingThird Party Advisory
FAQ
What is CVE-2017-14390?
CVE-2017-14390 is a vulnerability with a CVSS score of 7.5 (HIGH). In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained to unintended locations.
How severe is CVE-2017-14390?
CVE-2017-14390 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-14390?
Check the references section above for vendor advisories and patch information. Affected products include: Pivotal Software Cf-Deployment.