CVEs (37)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Feb 27, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user...Show more |
1Cloudfoundry 2Capi Release Cf DeploymentNov 21, 2024 Dec 19, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins. |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationNov 21, 2024 Dec 6, 2019 N/A· v4 6.5 MEDIUM· v3 3.5 LOW· v2 Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user crede...Show more |
1Cloudfoundry 2Cf Deployment User Account And AuthenticationNov 21, 2024 Nov 26, 2019 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Nov 19, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gor...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry Smb VolumeNov 21, 2024 Oct 23, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have be...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry UaaNov 21, 2024 Oct 23, 2019 N/A· v4 4.3 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content whic...Show more |
1Cloudfoundry 2Cf Deployment Nfs Volume ReleaseNov 21, 2024 Sep 23, 2019 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via...Show more |
1Cloudfoundry 3Cf Deployment CredhubUaa ReleaseNov 21, 2024 Apr 25, 2019 N/A· v4 9.8 CRITICAL· v3 5.0 MEDIUM· v2 Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entr...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry DiegoNov 21, 2024 Jun 6, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a comp...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 May 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an applicati...Show more |
2Cloudfoundry Pivotal Software3Cf Deployment Cloud Foundry UaaCloud Foundry Uaa ReleaseNov 21, 2024 May 15, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure...Show more |
1Cloudfoundry 2Cf Deployment Garden RuncNov 21, 2024 Apr 30, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space...Show more |
1Cloudfoundry 2Cf Deployment Garden Runc ReleaseNov 21, 2024 Mar 29, 2018 N/A· v4 8.8 HIGH· v3 3.5 LOW· v2 Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using thos...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Mar 19, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with...Show more |
1Cloudfoundry 3Capi Release Cf DeploymentCf ReleaseNov 21, 2024 Mar 19, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This...Show more |
1Cloudfoundry 3Capi Release Cf DeploymentCf ReleaseMay 13, 2026 Nov 28, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not pr...Show more |