Vulnerabilities > Cloudfoundry > Capi Release > High

DATE CVE VULNERABILITY TITLE RISK
2023-05-19 CVE-2023-20881 Improper Certificate Validation vulnerability in Cloudfoundry Capi-Release, Cf-Deployment and Loggregator-Agent
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain.
network
low complexity
cloudfoundry CWE-295
8.1
2020-12-02 CVE-2020-5423 Resource Exhaustion vulnerability in Cloudfoundry Capi-Release
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.
network
low complexity
cloudfoundry CWE-400
7.8