Show filters
59 Total Results
Displaying 11-20 of 59
Sort by:
Attacker Value
Unknown

CVE-2020-5416

Disclosure Date: August 21, 2020 (last updated February 22, 2025)
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool.
Attacker Value
Unknown

CVE-2020-15586

Disclosure Date: July 17, 2020 (last updated February 21, 2025)
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
Attacker Value
Unknown

CVE-2020-5400

Disclosure Date: February 24, 2020 (last updated February 21, 2025)
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.
Attacker Value
Unknown

CAPI leaks service broker URLs and GUIDs to space developers

Disclosure Date: December 19, 2019 (last updated November 27, 2024)
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
Attacker Value
Unknown

A forged route service request using an invalid nonce can cause the gorouter to…

Disclosure Date: November 19, 2019 (last updated November 27, 2024)
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
Attacker Value
Unknown

Volume Services is vulnerable to an LDAP injection attack

Disclosure Date: September 23, 2019 (last updated November 27, 2024)
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
Attacker Value
Unknown

CF CLI writes the client id and secret to config file

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
0
Attacker Value
Unknown

Java Projects using HTTP to fetch dependencies

Disclosure Date: April 25, 2019 (last updated November 27, 2024)
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
Attacker Value
Unknown

CVE-2016-0708

Disclosure Date: July 11, 2018 (last updated November 27, 2024)
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack versions for some basic web application archive (WAR) packaged applications are vulnerable to this issue.
0
Attacker Value
Unknown

CVE-2018-1193

Disclosure Date: May 23, 2018 (last updated November 26, 2024)
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
0