Vulnerabilities > Cloudfoundry > Routing Release > 0.172.0
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-09-08 | CVE-2023-34041 | Unspecified vulnerability in Cloudfoundry Routing-Release Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. | 5.3 |
2020-08-21 | CVE-2020-5416 | Improper Resource Shutdown or Release vulnerability in Cloudfoundry Cf-Deployment Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool. | 6.5 |
2020-07-17 | CVE-2020-15586 | Race Condition vulnerability in multiple products Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. | 5.9 |
2020-02-27 | CVE-2020-5401 | HTTP Request Smuggling vulnerability in Cloudfoundry Routing Release Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app. | 5.3 |
2019-11-19 | CVE-2019-11289 | Improper Input Validation vulnerability in Cloudfoundry Routing-Release Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. | 8.6 |
2019-04-24 | CVE-2019-3789 | Improper Privilege Management vulnerability in Cloudfoundry Routing Release Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. | 6.5 |
2018-05-23 | CVE-2018-1193 | Unspecified vulnerability in Cloudfoundry Routing-Release Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. | 5.3 |