← Back

CVE-2023-34041

nvd nist
Published: Sep 8, 2023Modified: Nov 21, 2024

JSON object

Loading...
5.3
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Exploitability: 3.9 / Impact: 1.4
Source: NVD

Description

Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.

Affected (2)

2 products
Cf Deployment
Routing Release
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Before 32.4.0
Before 0.278.0

Timeline

No history available yet.