CVE-2018-1191: Cloudfoundry Cf-Deployment

High severity, CVSS 8.8. EPSS: 0.9% chance of exploitation in the next 30 days.

Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.

Affected products

  • Cloudfoundry Cf-Deployment: before 1.9.0 (fixed in 1.9.0)
  • Cloudfoundry Garden-Runc-Release: before 1.11.0 (fixed in 1.11.0)

Published 2018-03-29. Last modified 2026-06-17.