Re: [security] CVE 2016-6655: Utility script command injection

Molly Crowther

Hello all - many people were asking for more information, so we have
prepared the following statement regarding CVE-2016-6655:


Molly Crowther

CFF Security Team


This issue was discovered by the IBM BlueMix team and was responsibly
reported to the Cloud Foundry Foundation.

A common script shared by many Cloud Foundry components includes some code
responsible for prepending timestamps to component logs. This code is
vulnerable to command injection in any component that logs user-provided
data. Critically it is possible for an attacker to craft a request to
gorouter that can execute arbitrary code as the VCAP user on the gorouter
VM. Gorouter logs should be examined for examples of shell-escape sequences
if operators suspect that their system may have been compromised. An
example woud be to url-encode a pipe (“|”) character followed by a
malicious command as in:
http://something.malicious). Note that this is only one of a number of ways
which an attacker could invoke an arbitrary command via this vulnerability.

Fixes were made to every CF component where this utility script is run.
Some components include this script but do not run it. Future updates will
remove the final unused instances of the vulnerable code to prevent
unintentional reintroduction.

Operators are strongly encouraged to upgrade to CF 245 or later and use the
most recent version of any standalone CF components.

For the original public notice regarding CVE-2016-6655, please see:

On Mon, Oct 17, 2016 at 8:34 AM, Travis McPeak

