Skip to main content

Vendor archive

cloudfoundry CVEs

Beta · best-effort

114 CVEs tagged to vendor cloudfoundry11 Critical, 58 High, 43 Medium, 2 Low, 0 Unrated.

CVE-2019-3775

Published Mar 7, 2019

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email a…

CVSS 7.1 · High
Vendor/product tagsBeta · best-effort

CVE-2019-3782

Published Feb 13, 2019

Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authe…

CVSS 7.8 · High
Vendor/product tagsBeta · best-effort

CVE-2018-11084

Published Sep 18, 2018

Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1269

Published Jun 6, 2018

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown w…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1268

Published Jun 6, 2018

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID stru…

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1267

Published Mar 27, 2018

Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) t…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2018-1266

Published Mar 27, 2018

Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the locat…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2015-5350

Published Mar 19, 2018

In Garden versions 0.22.0-0.329.0, a vulnerability has been discovered in the garden-linux nstar executable that allows access to files on the host system. By staging an applicati…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2017-8031

Published Nov 27, 2017

An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-75 of 114 CVEsPage 3 of 5