Vulnerabilities > Cloudfoundry > Routing Release > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-09-08 CVE-2023-34041 Unspecified vulnerability in Cloudfoundry Routing-Release
Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers.
network
low complexity
cloudfoundry
5.3
2023-05-26 CVE-2023-20882 Unspecified vulnerability in Cloudfoundry Cf-Deployment and Routing Release
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry.
network
high complexity
cloudfoundry
5.9
2020-08-21 CVE-2020-5416 Improper Resource Shutdown or Release vulnerability in Cloudfoundry Cf-Deployment
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool.
network
low complexity
cloudfoundry CWE-404
4.0
2020-07-17 CVE-2020-15586 Race Condition vulnerability in multiple products
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
5.9
2020-02-27 CVE-2020-5401 HTTP Request Smuggling vulnerability in Cloudfoundry Routing Release
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
network
low complexity
cloudfoundry CWE-444
5.0
2019-04-24 CVE-2019-3789 Improper Privilege Management vulnerability in Cloudfoundry Routing Release
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform.
network
low complexity
cloudfoundry CWE-269
4.0
2018-05-23 CVE-2018-1193 Unspecified vulnerability in Cloudfoundry Cf-Deployment and Routing-Release
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers.
network
low complexity
cloudfoundry
5.0
2018-03-19 CVE-2018-1221 Improper Input Validation vulnerability in Cloudfoundry Cf-Deployment
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers.
network
low complexity
cloudfoundry CWE-20
5.5
2017-07-17 CVE-2017-8034 Reliance on Cookies without Validation and Integrity Checking vulnerability in Cloudfoundry Capi-Release, Cf-Release and Routing-Release
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA.
6.0