Cloudfoundry
cloudfoundry
114 CVEs • 31 products
Products (31)
Click to collapseToggle
Products (31)
Click to collapse
CVEs (114)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unau...Show more |
1Cloudfoundry 1Routing Release Jun 17, 2026 Apr 24, 2019 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a priva...Show more |
1Cloudfoundry 1Bosh Backup And Restore Jun 17, 2026 Apr 24, 2019 N/A· v4 7.1 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and R...Show more |
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and kn...Show more |
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed...Show more |
1Cloudfoundry 1Container Runtime Jun 17, 2026 Mar 8, 2019 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allo...Show more |
1Cloudfoundry 1Container Runtime Jun 17, 2026 Mar 8, 2019 N/A· v4 8.8 HIGH· v3 4.0 MEDIUM· v2 Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user a...Show more |
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated...Show more |
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on be...Show more |
1Cloudfoundry 1Command Line Interface Jun 17, 2026 Mar 7, 2019 N/A· v4 8.8 HIGH· v3 3.5 LOW· v2 Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or al...Show more |
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. |
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to th...Show more |
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attribu...Show more |
1Cloudfoundry 2Cf Release Java BuildpackNov 21, 2024 Jul 11, 2018 N/A· v4 5.9 MEDIUM· v3 4.3 MEDIUM· v2 Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications...Show more |
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests....Show more |
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated...Show more |
2Cloudfoundry Pivotal Software2Cf Deployment Cloud Foundry DiegoNov 21, 2024 Jun 6, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a comp...Show more |
1Cloudfoundry 2Cf Deployment Routing ReleaseNov 21, 2024 May 23, 2018 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an applicati...Show more |
2Cloudfoundry Pivotal Software3Cf Deployment Cloud Foundry UaaCloud Foundry Uaa ReleaseNov 21, 2024 May 15, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure...Show more |
1Cloudfoundry 2Cf Deployment Garden RuncNov 21, 2024 Apr 30, 2018 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space...Show more |