CVE-2018-1277

MEDIUM

Cloud Foundry Garden-runC < 1.13.0 - Authenticated Denial of Service via Docker Image Layer Quota Bypass

Title source: llm
STIX 2.1

Description

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2018-1277/

Scores

CVSS v3 6.5
EPSS 0.0112
EPSS Percentile 62.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-400
Status published
Products (2)
cloudfoundry/cf-deployment < 1.28.0
cloudfoundry/garden-runc < 1.13.0
Published Apr 30, 2018
Tracked Since Feb 18, 2026