Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Bosh Cli HIGH 7.8
CVE-2026-47829

Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an op…

Fix: 7.10.4+
Fix from $1,950 2026-07-09
Bosh Cli CRITICAL 9.1
CVE-2026-47826

The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.…

Fix: 7.10.4+
Fix from $2,300 2026-07-09
Bosh Cli HIGH 8.8
CVE-2026-47828

During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS…

Fix: 7.10.4+
Fix from $1,950 2026-07-09
Bosh Cli HIGH 7.8
CVE-2026-41857

A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh …

Fix: 7.10.5+
Fix from $1,950 2026-07-09
Cf Deployment MEDIUM 5.0
CVE-2026-22726

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious dev…

Fix: 0.372.0 / 55.0.0+
Fix from $1,600 2026-05-01
Cf Deployment MEDIUM 6.5
CVE-2026-22723

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and …

Fix: 78.8.0+
Fix from $1,600 2026-03-05
Cf Deployment HIGH 7.5
CVE-2025-22246

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

Fix: 49.0.0 / 77.32.0+
Fix from $1,950 2025-05-13
Cf Deployment HIGH 7.5
CVE-2024-22279

Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability o…

Fix: after 40.13.0
Fix from $1,950 2024-06-10
Cf Deployment MEDIUM 5.3
CVE-2023-34041

Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this …

Fix: 0.278.0 / 32.4.0+
Fix from $1,600 2023-09-08
Cf Deployment MEDIUM 5.9
CVE-2023-20882

In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applicat…

Fix: 0.266.0 / 29.0.0+
Fix from $1,600 2023-05-26
Capi Release HIGH 8.1
CVE-2023-20881

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credenti…

Fix: after 29.0.0
Fix from $1,950 2023-05-19
Cf Deployment CRITICAL 9.1
CVE-2022-31733

Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on d…

Fix: after 23.2.0
Fix from $2,300 2023-02-03
Archiver CRITICAL 9.1
CVE-2018-25046

Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc…

Fix: 2018-05-23+
Fix from $2,300 2022-12-27
Capi Release MEDIUM 5.3
CVE-2021-22100

In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or malici…

Fix: 1.122.0 / 17.1.0+
Fix from $1,600 2022-03-25
Capi Release HIGH 7.5
CVE-2021-22101

Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers …

Fix: 1.118.0 / 16.24.0+
Fix from $1,950 2021-10-27
Cf Deployment MEDIUM 6.1
CVE-2021-22098

UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by…

Fix: 16.20.0 / 75.5.0+
Fix from $1,600 2021-08-11
Cf Deployment HIGH 7.5
CVE-2021-22001

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an iden…

Fix: 16.18.0 / 75.3.0+
Fix from $1,950 2021-07-22
Capi Release MEDIUM 6.5
CVE-2021-22115

Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI datab…

Fix: 1.106.0 / 16.2.0+
Fix from $1,600 2021-04-08
Capi Release HIGH 7.5
CVE-2020-5423

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can sen…

Fix: 1.101.0 / 15.0.0+
Fix from $1,950 2020-12-02
Cf Deployment HIGH 7.7
CVE-2020-5420

Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF clu…

Fix: 0.206.0 / 13.15.0+
Fix from $1,950 2020-09-03
Capi Release HIGH 8.8
CVE-2020-5417

Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is tr…

Fix: 1.97.0 / 13.12.0+
Fix from $1,950 2020-08-21
Cf Deployment MEDIUM 6.5
CVE-2020-5416

Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is poten…

Fix: 0.204.0 / 13.13.0+
Fix from $1,600 2020-08-21
Cf Deployment HIGH 8.8
CVE-2020-5402

In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback func…

Fix: 12.33.0 / 74.14.0+
Fix from $1,950 2020-02-27
Capi Release MEDIUM 6.5
CVE-2020-5400

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in…

Fix: 1.91.0 / 12.33.0+
Fix from $1,600 2020-02-27
Routing Release MEDIUM 5.3
CVE-2020-5401

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching …

Fix: 0.197.0+
Fix from $1,600 2020-02-27
Credhub HIGH 7.4
CVE-2020-5399

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with acce…

Fix: 2.5.10 / 12.29.0+
Fix from $1,950 2020-02-12
Cf Deployment MEDIUM 6.5
CVE-2019-11293

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter…

Fix: 12.12.0 / 74.10.0+
Fix from $1,600 2019-12-06
Cf Deployment HIGH 7.5
CVE-2019-11290

Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide …

Fix: 12.10.0 / 74.8.0+
Fix from $1,950 2019-11-26
Cf Deployment HIGH 8.6
CVE-2019-11289

Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HT…

Fix: 0.193.0 / 12.8.0+
Fix from $1,950 2019-11-19
Cf Deployment HIGH 8.8
CVE-2019-11283

Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volu…

Fix: 2.0.3 / 12.2.0+
Fix from $1,950 2019-10-23