{"id":"CVE-2018-15800","details":"Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.","modified":"2026-07-08T14:14:42.668279Z","published":"2018-12-10T19:29:25.173Z","references":[{"type":"ADVISORY","url":"https://www.cloudfoundry.org/blog/cve-2018-15800"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry-incubator/bits-service-release","events":[{"introduced":"0"},{"fixed":"c4cacdf8f55c05f0e312124e46f15635b86232c1"}],"database_specific":{"cpe":"cpe:2.3:a:cloud_foundry:bits_service:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.18.0"}],"source":"CPE_RANGE"}}],"versions":["2.17.0-dev.1","2.17.0","2.16.0-dev.7","2.16.0-dev.6","2.16.0-dev.5","2.16.0-dev.4","2.16.0-dev.3","2.16.0-dev.2","2.16.0-dev.1","2.16.0","2.15.0-dev.9","2.15.0-dev.8","2.15.0-dev.7","2.15.0-dev.6","2.15.0-dev.5","2.15.0-dev.4","2.15.0-dev.3","2.15.0-dev.2","2.15.0-dev.1","2.15.0","2.14.0-dev.5","2.14.0-dev.4","2.14.0-dev.3","2.14.0-dev.2","2.14.0-dev.1","2.14.0","2.13.0-dev.5","2.13.0-dev.4","2.13.0-dev.3","2.13.0-dev.2","2.13.0-dev.1","2.13.0","2.12.0-dev.9","2.12.0-dev.8","2.12.0-dev.7","2.12.0-dev.6","2.12.0-dev.5","2.12.0-dev.4","2.12.0-dev.3","2.12.0-dev.2","2.12.0-dev.1","2.12.0","2.11.0-dev.7","2.11.0-dev.6","2.11.0-dev.5","2.11.0-dev.4","2.11.0-dev.3","2.11.0-dev.2","2.11.0-dev.1","2.11.0","2.10.0-dev.11","2.10.0-dev.10","2.10.0-dev.9","2.10.0-dev.8","2.10.0-dev.7","2.10.0-dev.6","2.10.0-dev.5","2.10.0-dev.4","2.10.0-dev.3","2.10.0-dev.2","2.10.0-dev.1","2.9.0-dev.8","2.10.0","2.9.0-dev.7","2.9.0-dev.6","2.9.0-dev.5","2.9.0-dev.4","2.9.0-dev.3","2.9.0-dev.2","2.9.0-dev.1","2.9.0","2.8.0-dev.19","2.8.0-dev.18","2.8.0-dev.17","2.8.0-dev.16","2.8.0-dev.15","2.8.0-dev.14","2.8.0-dev.13","2.8.0-dev.12","2.8.0-dev.10","2.8.0-dev.9","2.8.0-dev.8","2.8.0-dev.7","2.8.0-dev.6","2.8.0-dev.5","2.8.0-dev.4","2.8.0-dev.3","2.8.0-dev.1","2.8.0","2.7.0-dev.7","2.7.0-dev.6","2.7.0-dev.5","2.7.0-dev.4","2.7.0","2.6.0","2.5.0","2.4.0","2.3.0","1.9.0","1.8.0","1.7.0","1.6.0","1.5.0","1.4.0","1.3.0","1.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2018-15800.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N"}]}