CVE-2017-8038: Pivotal Software Credhub-Release

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.

Affected products

Published 2017-11-27. Last modified 2026-06-17.