{"id":"CVE-2017-8036","details":"An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.","modified":"2026-07-08T11:36:27.370633Z","published":"2017-07-24T18:29:00.247Z","references":[{"type":"ADVISORY","url":"http://www.securityfocus.com/bid/100002"},{"type":"ADVISORY","url":"https://www.cloudfoundry.org/cve-2017-8036/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/capi-release","events":[{"introduced":"c436eb99139b137a4559ad281cd0683169241a00"},{"last_affected":"c436eb99139b137a4559ad281cd0683169241a00"}],"database_specific":{"cpe":"cpe:2.3:a:cloudfoundry:capi-release:1.33.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"1.33.0"},{"last_affected":"1.33.0"}],"source":"CPE_STRING"}}],"versions":["1.33.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2017-8036.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}