cvedb.io
CVE-2016-6658
CRITICAL · CVSS 9.6
EPSS exploitation probability: 0%
Published 2018-03-29T22:29:00.477 · Last modified 2026-06-17T00:51:32.703

Summary

Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.

Affected products

cloudfoundry — cf-release

Does this affect you?

Add your gear to cvedb and we'll alert you only when cloudfoundry ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.