1 results (0.001 seconds)

CVSS: 8.1EPSS: 0%CPEs: 1EXPL: 0

Cloud Foundry Bits Service Release, versions prior to 2.14.0, uses an insecure hashing algorithm to sign URLs. A remote malicious user may obtain a signed URL and extract the signing key, allowing them complete read and write access to the the Bits Service storage. Cloud Foundry Bits Service Release, en versiones anteriores a la 2.14.0, utiliza un algoritmo de hash inseguro para firmar URL. Un usuario malicioso remoto puede obtener una URL firmada y extraer la clave de firma, lo que permite un acceso completo de lectura y escritura al almacenamiento de Bits Service. • https://www.cloudfoundry.org/blog/cve-2018-15796 • CWE-326: Inadequate Encryption Strength •