Privilege Escalation via IAAS Credential Exposure in Cloud Foundry Container Runtime

Privilege Escalation via IAAS Credential Exposure in Cloud Foundry Container Runtime

CVE-2019-3780 · HIGH Severity

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account.

Learn more about our User Device Pen Test.