RSS   Vulnerabilities for 'Cloud foundry php buildpack'   RSS

2016-09-17
 
CVE-2016-6639

CWE-254
 

 
Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.38 and 1.7.x before 1.7.19 and other products, place the .profile file in the htdocs directory, which might allow remote attackers to obtain sensitive information via an HTTP GET request for this file.

 

 >>> Vendor: Pivotal 22 Products
Tc server
Operations manager
Spring framework
Rabbitmq
Cloud foundry elastic runtime
Cloud foundry
Cf-release
Capi-release
Bosh stemcell
Spring security oauth
Routing-release
Spring web flow
Pcf tile generator
UAA
Elastic runtime
Uaa-release
Uaa bosh
Spring-flex
Cloud foundry php buildpack
Tc runtimes
Reactor netty
Vmware harbor registry


Copyright 2024, cxsecurity.com

 

Back to Top