Vulnerabilities > Cloudfoundry > CF Deployment > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-10-23 | CVE-2019-11283 | Information Exposure Through Log Files vulnerability in multiple products Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. | 8.8 |
2019-09-23 | CVE-2019-11277 | Injection vulnerability in Cloudfoundry Cf-Deployment and NFS Volume Release Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. | 8.1 |
2018-06-06 | CVE-2018-1265 | Unrestricted Upload of File with Dangerous Type vulnerability in multiple products Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. | 7.2 |
2018-05-15 | CVE-2018-1262 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. | 7.2 |
2018-03-29 | CVE-2018-1191 | Information Exposure vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc-Release Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. | 8.8 |
2018-03-19 | CVE-2018-1221 | Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. | 8.1 |
2018-03-19 | CVE-2018-1195 | Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. | 8.8 |