CVE-2016-4435

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read or write blobs or cause a denial of service attack on the Director VM. This vulnerability requires that the unauthenticated clients guess or find a URL matching an existing GUID.
References
Link Resource
https://pivotal.io/security/cve-2016-4435 Third Party Advisory
https://pivotal.io/security/cve-2016-4435 Third Party Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:pivotal:bosh_stemcell:*:*:*:*:*:*:*:*
cpe:2.3:a:pivotal:bosh_stemcell:3146.13:*:*:*:*:*:*:*

History

21 Nov 2024, 02:52

Type Values Removed Values Added
References () https://pivotal.io/security/cve-2016-4435 - Third Party Advisory () https://pivotal.io/security/cve-2016-4435 - Third Party Advisory

Information

Published : 2017-05-25 17:29

Updated : 2024-11-21 02:52


NVD link : CVE-2016-4435

Mitre link : CVE-2016-4435

CVE.ORG link : CVE-2016-4435


JSON object : View

Products Affected

pivotal

  • bosh_stemcell
CWE
CWE-264

Permissions, Privileges, and Access Controls