« Volver al listado

CVE-2020-5418

Estado: ModificadaMedia (4.3)—

Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5418",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 4,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:N/A:N",
          "authentication": "SINGLE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@pivotal.io",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@pivotal.io",
      "affectedData": [
        {
          "vendor": "Cloud Foundry",
          "product": "CAPI",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "1.98.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Cloud Foundry",
          "product": "CF Deployment",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "13.17.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-09-03T01:15:10.763",
  "references": [
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2020-5418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@pivotal.io"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2020-5418",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@pivotal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-863"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the \"cloud_controller.read\" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none)."
    },
    {
      "lang": "es",
      "value": "Cloud Foundry CAPI (Cloud Controller) versiones  anteriores a 1.98.0, permiten a usuarios autenticados que solo tienen el alcance de \"cloud_controller.read\", pero sin roles en ningún espacio, listar todos los droplets en todos los espacios (mientras que no deberían visualizar ninguno)"
    }
  ],
  "lastModified": "2026-06-17T03:21:27.473",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3740EBD6-B639-48A4-BD12-F816793B7491",
              "versionEndExcluding": "1.98.0"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "647E4DBF-E906-432B-8C59-C6466CA818F4",
              "versionEndExcluding": "13.17.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@pivotal.io"
}