CVE-2017-8038: Pivotal Software Credhub-Release
High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.
In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential within the CredHub installation.
Affected products
- Pivotal Software Credhub-Release: version 1.1.0 only
Published 2017-11-27. Last modified 2026-06-17.