CVEs (35)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions pri...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prio...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry UaaCloud Foundry Uaa BoshMay 13, 2026 Jun 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prio...Show more |
1Cloudfoundry 2Cf Release Staticfile BuildpackMay 13, 2026 Jun 13, 2017 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static file build pack causes the Staticfile.auth configuration to be...Show more |
1Cloudfoundry 2Capi Release Cf ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage application...Show more |
1Cloudfoundry 2Cf Release Routing ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attac...Show more |
1Cloudfoundry 2Cf Mysql Release Cf ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by man...Show more |
2Cloudfoundry Pivotal Software2Cf Release Cloud Foundry Elastic RuntimeMay 13, 2026 May 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and...Show more |
2Cloudfoundry Pivotal Software2Cf Release Cloud Foundry Elastic RuntimeMay 13, 2026 May 25, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry Elastic RuntimeCloud Foundry UaaMay 13, 2026 May 25, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the change_email form in UAA is vulnerable to a CSRF attack. Thi...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry Elastic RuntimeCloud Foundry UaaMay 13, 2026 May 25, 2017 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which all...Show more |
2Cloudfoundry Pivotal Software3Cf Release Cloud Foundry Elastic RuntimeCloud Foundry UaaMay 13, 2026 May 25, 2017 N/A· v4 3.7 LOW· v3 4.3 MEDIUM· v2 With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes...Show more |
2Cloudfoundry Pivotal Software2Cf Release Cloud Foundry Elastic RuntimeMay 13, 2026 May 25, 2017 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2. Path travers...Show more |
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks. |
1Cloudfoundry 2Capi Release Cf ReleaseMay 13, 2026 Jan 13, 2017 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller syste...Show more |