Vulnerabilities > Cloudfoundry > Routing Release > High

DATE CVE VULNERABILITY TITLE RISK
2024-06-10 CVE-2024-22279 HTTP Request Smuggling vulnerability in Cloudfoundry Cf-Deployment and Routing Release
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale.
network
low complexity
cloudfoundry CWE-444
7.5
2019-11-19 CVE-2019-11289 Improper Input Validation vulnerability in Cloudfoundry Routing-Release
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input.
network
low complexity
cloudfoundry CWE-20
8.6
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
8.1