Vulnerabilities > Cloudfoundry > CF Release > Medium

DATE CVE VULNERABILITY TITLE RISK
2018-07-11 CVE-2016-0708 Information Exposure vulnerability in Cloudfoundry Cf-Release and Java Buildpack
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details.
4.3
2018-04-18 CVE-2016-2169 Code vulnerability in Cloudfoundry Capi-Release and Cf-Release
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw.
network
low complexity
cloudfoundry CWE-17
5.0
2018-03-29 CVE-2016-6658 Information Exposure vulnerability in multiple products
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack.
network
low complexity
cloudfoundry pivotal-software CWE-200
4.0
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
6.5
2018-01-04 CVE-2018-1190 Cross-site Scripting vulnerability in multiple products
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0.
4.3
2017-11-28 CVE-2017-14389 Unspecified vulnerability in Cloudfoundry Capi-Release
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0).
network
low complexity
cloudfoundry
4.0
2017-10-24 CVE-2015-5173 Information Exposure vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage."
6.8
2017-10-24 CVE-2015-5170 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
6.8
2017-10-04 CVE-2017-8048 In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. 6.8
2017-10-04 CVE-2017-8047 Open Redirect vulnerability in multiple products
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect.
5.8