Vulnerabilities > Cloudfoundry
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-10 | CVE-2024-22279 | HTTP Request Smuggling vulnerability in Cloudfoundry Cf-Deployment and Routing Release Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale. | 7.5 |
2023-09-08 | CVE-2023-34041 | Unspecified vulnerability in Cloudfoundry Routing-Release Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. | 5.3 |
2023-05-26 | CVE-2023-20882 | Unspecified vulnerability in Cloudfoundry Cf-Deployment and Routing Release In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. | 5.9 |
2023-05-19 | CVE-2023-20881 | Improper Certificate Validation vulnerability in Cloudfoundry Capi-Release, Cf-Deployment and Loggregator-Agent Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. | 8.1 |
2023-03-28 | CVE-2023-20903 | Insufficient Session Expiration vulnerability in Cloudfoundry User Account and Authentication This disclosure regards a vulnerability related to UAA refresh tokens and external identity providers.Assuming that an external identity provider is linked to the UAA, a refresh token is issued to a client on behalf of a user from that identity provider, the administrator of the UAA deactivates the identity provider from the UAA. | 4.3 |
2023-02-03 | CVE-2022-31733 | Improper Certificate Validation vulnerability in Cloudfoundry Cf-Deployment and Diego Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. | 9.1 |
2022-12-27 | CVE-2018-25046 | Path Traversal vulnerability in Cloudfoundry Archiver 20141016/20150319/20170223 Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target directory. | 9.1 |
2022-03-25 | CVE-2021-22100 | Resource Exhaustion vulnerability in Cloudfoundry Capi-Release In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. | 5.3 |
2021-10-27 | CVE-2021-22101 | Resource Exhaustion vulnerability in Cloudfoundry Capi-Release Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query. | 7.5 |
2021-08-11 | CVE-2021-22098 | Open Redirect vulnerability in Cloudfoundry User Account and Authentication UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. | 6.1 |