Vulnerabilities > Cloudfoundry > High

DATE CVE VULNERABILITY TITLE RISK
2019-03-07 CVE-2019-3783 Insecure Default Initialization of Resource vulnerability in Cloudfoundry Stratos
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret.
network
low complexity
cloudfoundry CWE-1188
8.8
2019-03-07 CVE-2019-3781 Information Exposure vulnerability in Cloudfoundry Command Line Interface
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on.
network
low complexity
cloudfoundry CWE-200
8.8
2019-02-13 CVE-2019-3782 Insufficiently Protected Credentials vulnerability in Cloudfoundry Credhub CLI
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file.
local
low complexity
cloudfoundry CWE-522
7.8
2018-06-06 CVE-2018-1265 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers.
network
low complexity
pivotal-software cloudfoundry CWE-434
7.2
2018-05-15 CVE-2018-1262 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation.
network
low complexity
pivotal-software cloudfoundry
7.2
2018-03-29 CVE-2018-1191 Information Exposure vulnerability in Cloudfoundry Cf-Deployment and Garden-Runc-Release
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
network
low complexity
cloudfoundry CWE-200
8.8
2018-03-27 CVE-2018-1267 Incorrect Permission Assignment for Critical Resource vulnerability in Cloudfoundry Silk-Release 0.1.0
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability.
network
high complexity
cloudfoundry CWE-732
8.1
2018-03-27 CVE-2018-1266 Use of Insufficiently Random Values vulnerability in Cloudfoundry Capi-Release
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities.
network
low complexity
cloudfoundry CWE-330
8.1
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
8.1
2018-03-19 CVE-2018-1195 Insufficient Session Expiration vulnerability in Cloudfoundry Cf-Release
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected.
network
low complexity
cloudfoundry CWE-613
8.8