Vulnerabilities > Cloudfoundry > CF Deployment

DATE CVE VULNERABILITY TITLE RISK
2018-03-29 CVE-2018-1191 Information Exposure vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc-Release
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
network
low complexity
cloudfoundry CWE-200
8.8
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
8.1
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
8.8
2017-11-28 CVE-2017-14389 Unspecified vulnerability in Cloudfoundry Cf-Release
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0).
network
low complexity
cloudfoundry
6.5