Vulnerabilities > Cloudfoundry > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-08-31 CVE-2016-0713 Cross-site Scripting vulnerability in Cloudfoundry Cf-Release
Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
network
high complexity
cloudfoundry CWE-79
4.7
2017-07-17 CVE-2017-8034 Reliance on Cookies without Validation and Integrity Checking vulnerability in Cloudfoundry Capi-Release and Cf-Release
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA.
network
high complexity
cloudfoundry CWE-565
6.6
2017-07-10 CVE-2017-8032 Improper Privilege Management vulnerability in multiple products
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to v24.12.
network
high complexity
pivotal-software cloudfoundry CWE-269
6.6
2017-06-13 CVE-2017-4974 SQL Injection vulnerability in multiple products
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior to v24.8, and other versions prior to v30.1.
network
low complexity
pivotal-software cloudfoundry CWE-89
6.5
2017-06-13 CVE-2017-4970 Unspecified vulnerability in Cloudfoundry Cf-Release and Staticfile Buildpack
An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3.
network
high complexity
cloudfoundry
5.9
2017-06-13 CVE-2016-8219 Improper Privilege Management vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0.
network
low complexity
cloudfoundry CWE-269
6.5
2017-05-25 CVE-2016-2165 Improper Input Validation vulnerability in multiple products
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response.
network
low complexity
pivotal-software cloudfoundry CWE-20
6.5
2017-05-25 CVE-2016-0781 Cross-site Scripting vulnerability in multiple products
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes (SCIM groups) or SCIM group descriptions.
network
low complexity
pivotal-software cloudfoundry CWE-79
6.1
2017-05-25 CVE-2015-3190 Open Redirect vulnerability in multiple products
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert malicious web page as a redirect parameter.
network
low complexity
pivotal-software cloudfoundry CWE-601
6.1
2017-05-25 CVE-2015-1834 Path Traversal vulnerability in multiple products
A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2.
network
low complexity
pivotal-software cloudfoundry CWE-22
6.5