Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.
{
"unresolved_ranges": [
{
"extracted_events": [
{
"fixed": "245"
}
],
"cpes": [
"cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*"
],
"vendor_product": "cloudfoundry:cf-release",
"source": "CPE_RANGE"
},
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*"
],
"vendor_product": "pivotal_software:cloud_foundry_elastic_runtime",
"extracted_events": [
{
"fixed": "1.6.49"
},
{
"fixed": "1.6.49"
},
{
"introduced": "1.7.0"
},
{
"fixed": "1.7.31"
},
{
"introduced": "1.7.0"
},
{
"fixed": "1.7.31"
},
{
"introduced": "1.8.0"
},
{
"fixed": "1.8.11"
},
{
"introduced": "1.8.0"
},
{
"fixed": "1.8.11"
}
]
}
]
}