CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cloudfoundry 2Cf Deployment Routing ReleaseMay 4, 2026 May 1, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that...Show more |
1Cloudfoundry 2Cf Deployment Uaa ReleaseMay 10, 2026 Mar 5, 2026 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0. |
1Cloudfoundry 2Cf Deployment Uaa ReleaseJul 11, 2025 May 13, 2025 N/A· v4 7.5 HIGH· v3 N/A· v2 Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Jun 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade
the service availability of the Cloud Foundry deployment if performed at scale. |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Sep 8, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identifi...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseJan 16, 2025 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when clien...Show more |
1Cloudfoundry 3Capi Release Cf DeploymentLoggregator AgentJan 21, 2025 May 19, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog dra...Show more |
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate....Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Mar 25, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Oct 27, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selec...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationNov 21, 2024 Aug 11, 2021 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certai...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationNov 21, 2024 Jul 22, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server. |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Apr 8, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Dec 2, 2020 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML p...Show more |
1Cloudfoundry 2Cf Deployment GorouterNov 21, 2024 Sep 3, 2020 N/A· v4 7.7 HIGH· v3 6.8 MEDIUM· v2 Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses th...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Sep 3, 2020 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Aug 21, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developer...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthentica...Show more |
5Cloudfoundry DebianFedoraproject+2 more6Cf Deployment Debian LinuxFedora+3 moreNov 21, 2024 Jul 17, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationNov 21, 2024 Feb 27, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback function when authenticating with external identity providers. |