Vulnerabilities > Cloudfoundry > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-10-24 CVE-2015-5170 Cross-Site Request Forgery (CSRF) vulnerability in multiple products
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks.
6.8
2017-10-04 CVE-2017-8048 In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application. 6.8
2017-10-04 CVE-2017-8047 Open Redirect vulnerability in multiple products
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect.
5.8
2017-09-07 CVE-2016-0732 Improper Privilege Management vulnerability in multiple products
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations on a different zone via unspecified vectors.
network
low complexity
cloudfoundry pivotal CWE-269
6.5
2017-08-31 CVE-2016-0713 Cross-site Scripting vulnerability in Cloudfoundry Cf-Release
Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
network
high complexity
cloudfoundry CWE-79
4.7
2017-08-21 CVE-2017-8037 Information Exposure vulnerability in Cloudfoundry Capi-Release and Cf-Release
In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035.
network
low complexity
cloudfoundry CWE-200
5.0
2017-07-25 CVE-2017-8035 Information Exposure vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268.
network
low complexity
cloudfoundry CWE-200
5.0
2017-07-25 CVE-2017-8033 Path Traversal vulnerability in Cloudfoundry Capi-Release and Cf-Release
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268.
6.8
2017-07-24 CVE-2017-8036 Unspecified vulnerability in Cloudfoundry Capi-Release 1.33.0
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only).
network
cloudfoundry
6.8
2017-07-17 CVE-2017-8034 Reliance on Cookies without Validation and Integrity Checking vulnerability in Cloudfoundry Capi-Release, Cf-Release and Routing-Release
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA.
6.0