Vulnerabilities > Cloudfoundry > CF Deployment > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-05-15 CVE-2018-1262 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation.
network
low complexity
pivotal-software cloudfoundry
6.5
2018-04-30 CVE-2018-1277 Resource Exhaustion vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers.
network
low complexity
cloudfoundry CWE-400
4.0
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
5.5
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
6.5
2017-11-28 CVE-2017-14389 Unspecified vulnerability in Cloudfoundry Capi-Release
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0).
network
low complexity
cloudfoundry
4.0