Vulnerabilities > Cloudfoundry

DATE CVE VULNERABILITY TITLE RISK
2018-04-18 CVE-2016-2169 Code vulnerability in Cloudfoundry Capi-Release and Cf-Release
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw.
network
low complexity
cloudfoundry CWE-17
5.0
2018-03-29 CVE-2016-6658 Information Exposure vulnerability in multiple products
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack.
network
low complexity
cloudfoundry pivotal-software CWE-200
4.0
2018-03-29 CVE-2018-1191 Information Exposure vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc-Release
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
3.5
2018-03-27 CVE-2018-1267 Incorrect Permission Assignment for Critical Resource vulnerability in Cloudfoundry Silk-Release 0.1.0
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability.
6.8
2018-03-27 CVE-2018-1266 Use of Insufficiently Random Values vulnerability in Cloudfoundry Capi-Release
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities.
network
low complexity
cloudfoundry CWE-330
6.5
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
5.5
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
6.5
2018-03-19 CVE-2015-5350 Improper Access Control vulnerability in Cloudfoundry Garden 0.22.0/0.329.0
In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system.
network
low complexity
cloudfoundry CWE-284
5.0
2018-01-04 CVE-2018-1190 Cross-site Scripting vulnerability in multiple products
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0.
4.3
2017-11-28 CVE-2017-14389 Unspecified vulnerability in Cloudfoundry Capi-Release
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0).
network
low complexity
cloudfoundry
4.0