Vulnerabilities > Cloudfoundry > Capi Release > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-03-25 | CVE-2021-22100 | Resource Exhaustion vulnerability in Cloudfoundry Capi-Release In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. | 5.3 |
2021-04-08 | CVE-2021-22115 | Insufficiently Protected Credentials vulnerability in Cloudfoundry Capi-Release Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. | 6.5 |
2020-09-03 | CVE-2020-5418 | Incorrect Authorization vulnerability in Cloudfoundry Capi-Release Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none). | 4.3 |
2020-02-27 | CVE-2020-5400 | Information Exposure Through Log Files vulnerability in Cloudfoundry Cf-Deployment Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. | 6.5 |
2019-12-19 | CVE-2019-11294 | Incorrect Authorization vulnerability in Cloudfoundry Cf-Deployment Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. | 4.3 |
2018-04-18 | CVE-2016-2169 | Code vulnerability in Cloudfoundry Capi-Release and Cf-Release Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. | 5.3 |
2017-11-28 | CVE-2017-14389 | Unspecified vulnerability in Cloudfoundry Cf-Release An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). | 6.5 |
2017-07-17 | CVE-2017-8034 | Reliance on Cookies without Validation and Integrity Checking vulnerability in Cloudfoundry Capi-Release and Cf-Release The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. | 6.6 |
2017-06-13 | CVE-2016-8219 | Improper Privilege Management vulnerability in Cloudfoundry Capi-Release and Cf-Release An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. | 6.5 |