Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps.
Link | Tags |
---|---|
https://www.cloudfoundry.org/blog/cve-2018-11084/ | mitigation vendor advisory |