Vulnerabilities > Cloudfoundry > CF Deployment > 1.33.0

DATE CVE VULNERABILITY TITLE RISK
2019-09-23 CVE-2019-11277 Injection vulnerability in Cloudfoundry Cf-Deployment and NFS Volume Release
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection.
network
low complexity
cloudfoundry CWE-74
8.1
2019-04-25 CVE-2019-3801 Cleartext Transmission of Sensitive Information vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building.
network
low complexity
cloudfoundry CWE-319
critical
9.8
2018-06-06 CVE-2018-1265 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers.
network
low complexity
pivotal-software cloudfoundry CWE-434
7.2