Security Advisory

CVE-2019-3786

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2019-04-24 15:21:10
Last updated 2024-09-17 02:15:38
Assigner dell
State PUBLISHED

Description

Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in this metadata script were only maintained in the cfcr-etcd-release, so clusters deployed with the BBR job for etcd in this release are vulnerable.