Vulnerabilities > Cloudfoundry > CF Release > 267

DATE CVE VULNERABILITY TITLE RISK
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
6.5
2018-01-04 CVE-2018-1190 Cross-site Scripting vulnerability in multiple products
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0.
4.3
2017-11-28 CVE-2017-14389 Unspecified vulnerability in Cloudfoundry Capi-Release
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0).
network
low complexity
cloudfoundry
4.0
2017-11-27 CVE-2017-8031 Unspecified vulnerability in Cloudfoundry Cf-Release
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1).
network
cloudfoundry
3.5
2017-10-04 CVE-2017-8047 Open Redirect vulnerability in multiple products
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect.
5.8
2017-08-21 CVE-2017-8037 Information Exposure vulnerability in Cloudfoundry Capi-Release and Cf-Release
In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035.
network
low complexity
cloudfoundry CWE-200
5.0
2017-07-25 CVE-2017-8035 Information Exposure vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268.
network
low complexity
cloudfoundry CWE-200
5.0
2017-07-25 CVE-2017-8033 Path Traversal vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268.
6.8
2017-06-13 CVE-2017-4974 SQL Injection vulnerability in multiple products
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1.
network
low complexity
pivotal-software cloudfoundry CWE-89
4.0