Skip to main content

Vendor archive

cloud_foundry CVEs

Beta · best-effort

9 CVEs tagged to vendor cloud_foundry0 Critical, 5 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2026-41704

Published May 27, 2026

AgentClient#handle_method (lines 264-303) processes every NATS reply. It calls inject_compile_log (line 273) on every response, which reads response['value']['result']['compile_lo…

CVSS 6.8 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2026-41009

Published May 27, 2026

When the director sends a long-running request (e.g. compile_package), the agent's reply JSON is consumed by AgentClient. inject_compile_log (line 332-339) reads response['value']…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2019-11271

Published Jun 19, 2019

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticat…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15800

Published Dec 10, 2018

Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the sign…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-15755

Published Oct 12, 2018

Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A rem…

CVSS 6.6 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-11083

Published Oct 5, 2018

Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2017-4961

Published Jun 13, 2017

An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2016-3091

Published Jun 8, 2017

Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1