Show filters
69 Total Results
Displaying 1-10 of 69
Sort by:
Attacker Value
Unknown

CVE-2025-22216

Disclosure Date: January 31, 2025 (last updated January 31, 2025)
A UAA configured with multiple identity zones, does not properly validate session information across those zones. A User authenticated against a corporate IDP can re-use their jsessionid to access other zones.
0
Attacker Value
Unknown

CVE-2024-38826

Disclosure Date: November 11, 2024 (last updated November 11, 2024)
Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller. The Cloud Foundry project recommends upgrading the following releases: * Upgrade capi release version to 1.194.0 or greater * Upgrade cf-deployment version to v44.1.0 or greater. This includes a patched capi release
0
Attacker Value
Unknown

CVE-2023-34061

Disclosure Date: January 12, 2024 (last updated January 19, 2024)
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.
Attacker Value
Unknown

CVE-2023-20885

Disclosure Date: June 16, 2023 (last updated October 08, 2023)
Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications: All versions prior to 63; SMB-volume release: All versions prior to 3.1.19; cf-nfs-volume release: 5.0.X versions prior to 5.0.27, 7.1.X versions prior to 7.1.19.
Attacker Value
Unknown

CVE-2020-5399

Disclosure Date: February 12, 2020 (last updated February 21, 2025)
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
Attacker Value
Unknown

UAA is vulnerable to a Blind SCIM injection leading to information disclosure

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about users of the UAA.
Attacker Value
Unknown

Password leak in smbdriver logs

Disclosure Date: October 23, 2019 (last updated November 27, 2024)
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
Attacker Value
Unknown

UAA clients.write vulnerability

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess.
Attacker Value
Unknown

CF CLI writes the client id and secret to config file

Disclosure Date: August 05, 2019 (last updated November 27, 2024)
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
0
Attacker Value
Unknown

UAA - Login app subject to clickjacking attack

Disclosure Date: July 18, 2019 (last updated November 27, 2024)
Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites.