{"id":"CVE-2016-6658","details":"Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.","modified":"2026-08-27T03:45:26.451963882Z","published":"2018-03-29T22:29:00.477Z","database_specific":{"unresolved_ranges":[{"source":"CPE_RANGE","vendor_product":"pivotal_software:cloud_foundry_elastic_runtime","cpes":["cpe:2.3:a:pivotal_software:cloud_foundry_elastic_runtime:*:*:*:*:*:*:*:*"],"extracted_events":[{"fixed":"1.6.49"},{"fixed":"1.6.49"},{"introduced":"1.7.0"},{"fixed":"1.7.31"},{"introduced":"1.7.0"},{"fixed":"1.7.31"},{"introduced":"1.8.0"},{"fixed":"1.8.11"},{"introduced":"1.8.0"},{"fixed":"1.8.11"}]}]},"references":[{"type":"ADVISORY","url":"https://pivotal.io/security/cve-2016-6658"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry-attic/cf-release","events":[{"introduced":"0"},{"fixed":"1a84cd71377a1ac645f76c686156142ea0685067"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"245"}]}}],"versions":["v205","v183","v170","v161","v157","v156","rc145.0","v143","works-for-us","v140","v137","v136","v135","v134","v133","v132","scotty_09012012","v119","v109","v105","v104","v103","v102","v100","v99","-","log","list"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2016-6658.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:N"}]}