CVE-2015-5350

HIGH

Garden <0.22.0-0.329.0 - Info Disclosure

Title source: llm
STIX 2.1

Description

In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an application on Cloud Foundry using Diego and Garden installations with a malicious custom buildpack an end user could read files on the host system that the BOSH-created vcap user has permissions to read and then package them into their app droplet.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://pivotal.io/security/cve-2015-5350

Scores

CVSS v3 7.5
EPSS 0.0132
EPSS Percentile 67.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-284
Status published
Products (1)
cloudfoundry/garden < 0.330.0
Published Mar 19, 2018
Tracked Since Feb 18, 2026