Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.34 and 1.7.x before 1.7.12 places 169.254.0.0/16 in the all_open Application Security Group, which might allow remote attackers to bypass intended network-connectivity restrictions by leveraging access to the 169.254.169.254 address.
{
"unresolved_ranges": [
{
"cpes": [
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"last_affected": "1.6.33"
},
{
"last_affected": "1.6.33"
}
],
"vendor_product": "pivotal_software:cloud_foundry_elastic_runtime",
"source": "CPE_RANGE"
},
{
"cpes": [
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.10:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.11:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.3:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.4:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.5:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.6:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.7:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.8:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.9:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.7.0"
},
{
"last_affected": "1.7.0"
},
{
"introduced": "1.7.3"
},
{
"last_affected": "1.7.3"
},
{
"introduced": "1.7.3"
},
{
"last_affected": "1.7.3"
},
{
"introduced": "1.7.4"
},
{
"last_affected": "1.7.4"
},
{
"introduced": "1.7.4"
},
{
"last_affected": "1.7.4"
},
{
"introduced": "1.7.5"
},
{
"last_affected": "1.7.5"
},
{
"introduced": "1.7.5"
},
{
"last_affected": "1.7.5"
},
{
"introduced": "1.7.6"
},
{
"last_affected": "1.7.6"
},
{
"introduced": "1.7.6"
},
{
"last_affected": "1.7.6"
},
{
"introduced": "1.7.7"
},
{
"last_affected": "1.7.7"
},
{
"introduced": "1.7.7"
},
{
"last_affected": "1.7.7"
},
{
"introduced": "1.7.8"
},
{
"last_affected": "1.7.8"
},
{
"introduced": "1.7.8"
},
{
"last_affected": "1.7.8"
},
{
"introduced": "1.7.9"
},
{
"last_affected": "1.7.9"
},
{
"introduced": "1.7.9"
},
{
"last_affected": "1.7.9"
},
{
"introduced": "1.7.10"
},
{
"last_affected": "1.7.10"
},
{
"introduced": "1.7.10"
},
{
"last_affected": "1.7.10"
},
{
"introduced": "1.7.11"
},
{
"last_affected": "1.7.11"
},
{
"introduced": "1.7.11"
},
{
"last_affected": "1.7.11"
}
],
"vendor_product": "pivotal_software:cloud_foundry_elastic_runtime",
"source": "CPE_STRING"
}
]
}{
"cpe": [
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.0:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.1:*:*:*:*:*:*:*",
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:1.7.2:*:*:*:*:*:*:*"
],
"extracted_events": [
{
"introduced": "1.7.0"
},
{
"last_affected": "1.7.0"
},
{
"introduced": "1.7.1"
},
{
"last_affected": "1.7.1"
},
{
"introduced": "1.7.2"
},
{
"last_affected": "1.7.2"
}
],
"source": "CPE_STRING"
}