CVE-2018-1277
MEDIUMCloud Foundry Garden-runC < 1.13.0 - Authenticated Denial of Service via Docker Image Layer Quota Bypass
Title source: llmDescription
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2018-1277/
Scores
CVSS v3
6.5
EPSS
0.0112
EPSS Percentile
62.0%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Details
CWE
CWE-400
Status
published
Products (2)
cloudfoundry/cf-deployment
< 1.28.0
cloudfoundry/garden-runc
< 1.13.0
Published
Apr 30, 2018
Tracked Since
Feb 18, 2026