Vulnerabilities > CVE-2020-5420 - Improper Check for Unusual or Exceptional Conditions vulnerability in Cloudfoundry Cf-Deployment and Gorouter

047910
CVSS 7.7 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
LOW
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
cloudfoundry
CWE-754

Summary

Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters.

Vulnerable Configurations

Part Description Count
Application
Cloudfoundry
213