An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.
During installation, installed file permissions are set to allow anyone to modify those files.
Link | Tags |
---|---|
https://pivotal.io/security/cve-2017-4975 | mitigation vendor advisory |