Skip to main content

Vendor archive

cloudfoundry CVEs

Beta · best-effort

114 CVEs tagged to vendor cloudfoundry11 Critical, 58 High, 43 Medium, 2 Low, 0 Unrated.

CVE-2020-5401

Published Feb 27, 2020

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent le…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-11279

Published Sep 26, 2019

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their ow…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3788

Published Apr 25, 2019

Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3789

Published Apr 24, 2019

Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3798

Published Apr 17, 2019

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-3785

Published Mar 13, 2019

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3780

Published Mar 8, 2019

Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3779

Published Mar 8, 2019

Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3784

Published Mar 7, 2019

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3783

Published Mar 7, 2019

Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3781

Published Mar 7, 2019

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious use…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort
Showing 26-50 of 114 CVEsPage 2 of 5