漏洞详情: CVE-2016-0708

漏洞标题
NVD 暂无描述信息
来源:NVD
Cloud Foundry和Cloud Foundry Java Buildpack 信息泄露漏洞
来源:CNNVD
漏洞描述
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue.
来源:NVD
Cloud Foundry和Cloud Foundry Java Buildpack都是美国Cloud Foundry基金会的产品。Cloud Foundry是一套开源的平台即服务(PaaS)云计算平台,它提供容器调度、持续交付和自动化服务部署等功能。Cloud Foundry Java Buildpack是一套用于运行Java应用程序的环境。 Cloud Foundry 166版本至227版本和Cloud Foundry Java Buildpack 2.0版本至3.4版本中存在信息泄露漏洞。攻击者可利
来源:CNNVD
部署到Cloud Foundry的应用,包括v166到v227版本,可能受到远程泄露信息的影响,包括但不限于环境变量和绑定的服务细节。为了让应用有风险,它们必须通过自动构建包检测进行预构建,通过Java构建包检测脚本进行验证,并允许从部署的 artifact 中 serving 静态内容。受影响的一些基本Web应用程序包(WAR)应用程序的默认Apache Tomcat配置可能 vulnerable to this issue。
来源:神龙机器人
漏洞评分(CVSS)
NVD 暂无评分
来源:NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
来源:神龙机器人, 准确率:N/A
漏洞类别
NVD 暂无漏洞类别信息
来源:NVD
信息泄露
来源:CNNVD
相关链接