{"id":"CVE-2018-1265","details":"Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.","modified":"2026-07-08T17:57:14.368141Z","published":"2018-06-06T20:29:00.470Z","references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2018-1265/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/cf-deployment","events":[{"introduced":"0"},{"fixed":"3b78cac999d03981c4f5c4a0dfefe6043019b059"}],"database_specific":{"cpe":"cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"1.37.0"}],"source":"CPE_RANGE"}}],"versions":["v1.36.0","v1.35.0","v1.34.0","v1.33.0","v1.32.0","v1.31.0","v1.30.0","v1.29.0","v1.28.0","v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.0","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.18.0","v1.16.0","v1.17.0","v1.15.0","v1.14.0","v1.13.0","v1.12.0","v1.11.0","v1.10.0","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v0.37.0","v1.0.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.28.0","v0.29.0","v0.15.0","v0.13.0","v0.14.0","v0.12.0","v0.11.0","v0.10.0","v0.9.1","v0.9.0","v0.8.0","v0.3.0","v0.7.0","v0.5.0","v0.2.1","v0.2.2","v0.2.0","v0.1.0","v0.0.2","v0.0.1","v0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1265.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/diego-release","events":[{"introduced":"0"},{"fixed":"51a69e2fdef06ed74ede717bbedf725879896325"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:pivotal_software:cloud_foundry_diego:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.8.0"}]}}],"versions":["v2.7.1","v2.7.0","v2.6.0","v2.5.0","v1.35.0","v1.32.1","v1.32.0","v1.30.0","v1.29.2","v1.29.1","v1.26.2","v1.26.1","v1.26.0","v1.24.0","v1.22.0","v1.21.0","v1.18.1","v1.17.0","v1.16.1","v1.15.2","v1.15.0","v1.14.0","v1.11.0","v1.10.0","v1.9.0","v1.6.2","v1.5.1","v1.5.0","v1.4.0","v1.3.1","v1.3.0","v1.0.0","v0.1491.0","v0.1490.0","v0.1489.0","v0.1488.0","v0.1487.0","v0.1486.0","v0.1485.0","v0.1484.0","v0.1483.0","v0.1482.0","v0.1480.0","v0.1473.0","v0.1472.0","v0.1471.0","v0.1469.0","v0.1468.0","v0.1460.0","v0.1459.0","v0.1458.0","v0.1457.0","v0.1455.0","v0.1454.0","v0.1453.0","v0.1452.0","v0.1450.0","v0.1449.0","v0.1448.0","v0.1447.0","v0.1441.0","v0.1440.0","v0.1439.0","v0.1438.0","v0.1437.0","v0.1434.0","0.1434.0","v0.1433.0","0.1433.0","v0.1432.0","0.1432.0","v0.1431.0","0.1431.0","v0.1430.0","0.1430.0","v0.1429.0","0.1429.0","v0.1427.0","0.1427.0","v0.1425.0","0.1425.0","v0.1423.0","0.1423.0","v0.1415.0","0.1415.0","v0.1412.0","0.1412.0","v0.1410.0","0.1410.0","v0.1401.0","0.1401.0","v0.1399.0","0.1399.0","v0.1398.0","0.1398.0","v0.1397.0","0.1397.0","v0.1394.0","0.1394.0","v0.1393.0","0.1393.0","v0.1392.0","0.1392.0","v0.1391.0","0.1391.0","v0.1390.0","0.1390.0","v0.1389.0","0.1389.0","v0.1386.0","0.1386.0","v0.1384.0","0.1384.0","v0.1383.0","0.1383.0","v0.1382.0","0.1382.0","v0.1371.0","0.1371.0","v0.1370.0","0.1370.0","v0.1369.0","0.1369.0","v0.1368.0","0.1368.0","v0.1367.0","0.1367.0","v0.1360.0","0.1360.0","v0.1353.0","0.1353.0","v0.1351.0","0.1351.0","v0.1345.0","0.1345.0","v0.1341.0","0.1341.0","v0.1340.0","0.1340.0","v0.1338.0","0.1338.0","v0.1337.0","0.1337.0","v0.1335.0","0.1335.0","v0.1332.0","0.1332.0","v0.1331.0","0.1331.0","v0.1329.0","0.1329.0","v0.1327.0","0.1327.0","v0.1324.0","0.1324.0","v0.1323.0","0.1323.0","v0.1319.0","0.1319.0","v0.1317.0","0.1317.0","v0.1313.0","0.1313.0","v0.1312.0","0.1312.0","v0.1311.0","0.1311.0","v0.1310.0","0.1310.0","v0.1309.0","0.1309.0","v0.1307.0","0.1307.0","v0.1306.0","0.1306.0","v0.1304.0","0.1304.0","v0.1303.0","0.1303.0","v0.1293.0","0.1293.0","v0.1290.0","0.1290.0","v0.1289.0","0.1289.0","v0.1285.0","0.1285.0","v0.1284.0","0.1284.0","v0.1283.0","0.1283.0","v0.1282.0","0.1282.0","v0.1281.0","0.1281.0","v0.1278.0","0.1278.0","v0.1277.0","0.1277.0","v0.1276.0","0.1276.0","v0.1266.0","0.1266.0","v0.1265.0","0.1265.0","v0.1264.0","0.1264.0","v0.1263.0","0.1263.0","v0.1262.0","0.1262.0","v0.1261.0","0.1261.0","v0.1259.0","0.1259.0","v0.1258.0","0.1258.0","v0.1257.0","0.1257.0","v0.1254.0","0.1254.0","v0.1251.0","0.1251.0","v0.1245.0","0.1245.0","v0.1244.0","0.1244.0","v0.1241.0","0.1241.0","v0.1240.0","0.1240.0","v0.1231.0","0.1231.0","v0.1225.0","0.1225.0","v0.1221.0","0.1221.0","v0.1209.0","0.1209.0","v0.1208.0","0.1208.0","v0.1206.0","0.1206.0","v0.1198.0","0.1198.0","v0.1197.0","0.1197.0","v0.1194.0","0.1194.0","v0.1193.0","0.1193.0","v0.1186.0","0.1186.0","v0.1185.0","0.1185.0","v0.1184.0","0.1184.0","v0.1183.0","0.1183.0","v0.1181.0","0.1181.0","v0.1179.0","0.1179.0","v0.1172.0","0.1172.0","v0.1166.0","0.1166.0","v0.1158.0","0.1158.0","v0.1157.0","0.1157.0","v0.1156.0","0.1156.0","v0.1155.0","0.1155.0","v0.1153.0","0.1153.0","v0.1152.0","0.1152.0","v0.1151.0","0.1151.0","v0.1150.0","0.1150.0","v0.1149.0","0.1149.0","v0.1148.0","0.1148.0","v0.1147.0","0.1147.0","v0.1146.0","0.1146.0","v0.1145.0","0.1145.0","v0.1144.0","0.1144.0","v0.1143.0","0.1143.0","v0.1142.0","0.1142.0","v0.1141.0","0.1141.0","v0.1140.0","0.1140.0","v0.1139.0","0.1139.0","v0.1138.0","0.1138.0","v0.1137.0","0.1137.0","v0.1135.0","0.1135.0","v0.1134.0","0.1134.0","v0.1132.0","0.1132.0","v0.1102.0","0.1102.0","v0.1101.0","0.1101.0","v0.1099.0","0.1099.0","v0.1097.0","0.1097.0","v0.1094.0","0.1094.0","v0.1093.0","0.1093.0","v0.1092.0","0.1092.0","v0.1090.0","0.1090.0","v0.1088.0","0.1088.0","v0.1087.0","0.1087.0","v0.1086.0","0.1086.0","v0.1085.0","0.1085.0","v0.1083.0","0.1083.0","v0.1082.0","0.1082.0","v0.1081.0","0.1081.0","v0.1077.0","0.1077.0","v0.1073.0","0.1073.0","v0.1072.0","0.1072.0","v0.1069.0","0.1069.0","v0.1068.0","0.1068.0","v0.1065.0","0.1065.0","v0.1064.0","0.1064.0","v0.1062.0","0.1062.0","v0.1061.0","0.1061.0","v0.1060.0","0.1060.0","v0.1059.0","0.1059.0","v0.1058.0","0.1058.0","v0.1056.0","0.1056.0","v0.1053.0","0.1053.0","v0.1052.0","0.1052.0","v0.1050.0","0.1050.0","v0.1049.0","0.1049.0","v0.1046.0","0.1046.0","v0.1045.0","0.1045.0","v0.1043.0","0.1043.0","v0.1039.0","0.1039.0","v0.1038.0","0.1038.0","v0.1037.0","0.1037.0","v0.1034.0","0.1034.0","v0.1030.0","0.1030.0","v0.1028.0","0.1028.0","v0.1026.0","0.1026.0","v0.1023.0","0.1023.0","v0.1022.0","0.1022.0","v0.1018.0","0.1018.0","v0.1016.0","0.1016.0","v0.1015.0","0.1015.0","v0.1014.0","0.1014.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-1265.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"}]}