AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2016-6658

CRITICAL · CVSS 9.6 EPSS 0.88%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-03-29 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2016-6658
Severity
CRITICAL
CVSS
9.6
EPSS
0.88%
GitHub

Original NVD Description

Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Controller database could view these credentials.