Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Uaa Release HIGH 8.8
CVE-2019-11279

CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malici…

Fix: 74.1.0+
Fix from $1,950 2019-09-26
User Account And Authentication HIGH 8.8
CVE-2019-11278

CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update'…

Fix: 74.1.0+
Fix from $1,950 2019-09-26
Cf Deployment HIGH 8.1
CVE-2019-11277

Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic…

Fix: 1.7.11 / 2.3.0+
Fix from $1,950 2019-09-23
User Account And Authentication MEDIUM 6.1
CVE-2019-11274

Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that conta…

Fix: 74.0.0+
Fix from $1,600 2019-08-09
Cf Deployment CRITICAL 9.8
CVE-2019-3801

Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building…

Fix: 1.9.10 / 2.1.3+
Fix from $2,300 2019-04-25
Uaa Release MEDIUM 6.1
CVE-2019-3788

Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w…

Fix: 71.0+
Fix from $1,600 2019-04-25
Routing Release MEDIUM 6.5
CVE-2019-3789

Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside t…

Fix: 0.188.0+
Fix from $1,600 2019-04-24
Bosh Backup And Restore HIGH 7.1
CVE-2019-3786

Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authentic…

Fix: 1.5.0+
Fix from $1,950 2019-04-24
Capi Release HIGH 7.5
CVE-2019-3798

Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut…

Fix: 1.79.0+
Fix from $1,950 2019-04-17
Capi Release HIGH 8.1
CVE-2019-3785

Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…

Fix: 1.78.0+
Fix from $1,950 2019-03-13
Container Runtime HIGH 8.8
CVE-2019-3779

Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust …

Fix: 0.29.0+
Fix from $1,950 2019-03-08
Container Runtime HIGH 8.8
CVE-2019-3780

Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malic…

Fix: 0.28.0+
Fix from $1,950 2019-03-08
Command Line Interface HIGH 8.8
CVE-2019-3781

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo…

Fix: 6.43.0+
Fix from $1,950 2019-03-07
Stratos HIGH 8.8
CVE-2019-3783

Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secre…

Fix: 2.3.0+
Fix from $1,950 2019-03-07
Uaa Release MEDIUM 6.5
CVE-2019-3775

Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different …

Fix: 70.0+
Fix from $1,600 2019-03-07
Stratos MEDIUM 6.5
CVE-2019-3784

Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instan…

Fix: 2.3.0+
Fix from $1,600 2019-03-07
Credhub Cli HIGH 7.8
CVE-2019-3782

Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persist…

Fix: 2.2.1+
Fix from $1,950 2019-02-13
Garden Runc MEDIUM 6.5
CVE-2018-11084

Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authentica…

Fix: 1.16.1+
Fix from $1,600 2018-09-18
Cf Release MEDIUM 5.9
CVE-2016-0708

Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limit…

Fix: after 227
Fix from $1,600 2018-07-11
Cf Deployment HIGH 7.2
CVE-2018-1265

Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a…

Fix: 1.37.0 / 2.8.0+
Fix from $1,950 2018-06-06
Loggregator MEDIUM 6.8
CVE-2018-1268

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…

Fix: 89.5 / 96.1+
Fix from $1,600 2018-06-06
Loggregator MEDIUM 6.5
CVE-2018-1269

Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…

Fix: 89.5 / 96.1+
Fix from $1,600 2018-06-06
Cf Deployment MEDIUM 5.3
CVE-2018-1193

Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X…

Fix: 0.175.0 / 1.27.0+
Fix from $1,600 2018-05-23
Garden Runc MEDIUM 6.5
CVE-2018-1277

Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may …

Fix: 1.13.0 / 1.28.0+
Fix from $1,600 2018-04-30
Capi Release MEDIUM 5.3
CVE-2016-2169

Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An applica…

Fix: 1.0.0 / 237+
Fix from $1,600 2018-04-18
Cf Release CRITICAL 9.6
CVE-2016-6658

Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho…

Fix: 1.6.49 / 1.7.31+
Fix from $2,300 2018-03-29
Cf Deployment HIGH 8.8
CVE-2018-1191

Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to…

Fix: 1.9.0 / 1.11.0+
Fix from $1,950 2018-03-29
Capi Release HIGH 8.1
CVE-2018-1266

Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malici…

Fix: 1.52.0+
Fix from $1,950 2018-03-27
Silk Release HIGH 8.1
CVE-2018-1267

Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an appl…

Fix: 0.2.0+
Fix from $1,950 2018-03-27
Capi Release HIGH 8.8
CVE-2018-1195

In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts r…

Fix: 1.3.0 / 1.46.0+
Fix from $1,950 2018-03-19