CVEs (13)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Cloudfoundry 2Cf Deployment Routing ReleaseMay 4, 2026 May 1, 2026 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Jun 10, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade
the service availability of the Cloud Foundry deployment if performed at scale. |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Sep 8, 2023 N/A· v4 5.3 MEDIUM· v3 N/A· v2 Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identifi...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseJan 16, 2025 May 26, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when clien...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Aug 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthentica...Show more |
5Cloudfoundry DebianFedoraproject+2 more6Cf Deployment Debian LinuxFedora+3 moreNov 21, 2024 Jul 17, 2020 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time. |
1Cloudfoundry 1Routing Release Nov 21, 2024 Feb 27, 2020 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Nov 19, 2019 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gor...Show more |
1Cloudfoundry 1Routing Release Nov 21, 2024 Apr 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a priva...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 May 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an applicati...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 Mar 19, 2018 N/A· v4 8.1 HIGH· v3 5.5 MEDIUM· v2 In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with...Show more |
1Cloudfoundry 3Capi Release Cf ReleaseRouting ReleaseMay 13, 2026 Jul 17, 2017 N/A· v4 6.6 MEDIUM· v3 6.0 MEDIUM· v2 The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens...Show more |
1Cloudfoundry 2Cf Release Routing ReleaseMay 13, 2026 Jun 13, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attac...Show more |