Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cf Release HIGH 7.5
CVE-2016-0780

It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elas…

Mitigation only
Fix from $1,950 2017-05-25
Cf Release MEDIUM 6.5
CVE-2015-1834

A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivo…

Fix: after 207
Fix from $1,600 2017-05-25
Cf Release MEDIUM 6.5
CVE-2016-2165

The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior …

Fix: after 231
Fix from $1,600 2017-05-25
Cf Release MEDIUM 6.1
CVE-2015-3190

With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or e…

Fix: after 209
Fix from $1,600 2017-05-25
Cloud Foundry Uaa Bosh MEDIUM 6.1
CVE-2016-0781

The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 …

Fix: after 2.7.4.1
Fix from $1,600 2017-05-25
Cf Release MEDIUM 6.5
CVE-2017-4969

The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tas…

Fix: after 254
Fix from $1,600 2017-04-20
Cloud Foundry Uaa Bosh HIGH 8.8
CVE-2016-4468

SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; UAA BOSH b…

Fix: after 237.0
Fix from $1,950 2017-04-11
Bosh Azure Cpi HIGH 8.8
CVE-2017-4964

Cloud Foundry Foundation BOSH Azure CPI v22 could potentially allow a maliciously crafted stemcell to execute arbitrary code on VMs created by the di…

Patch available
Fix from $1,950 2017-04-06
Cloud Foundry Uaa Bosh HIGH 7.5
CVE-2017-4960

An issue was discovered in Cloud Foundry release v247 through v252, UAA stand-alone release v3.9.0 through v3.11.0, and UAA Bosh Release v21 through …

Mitigation only
Fix from $1,950 2017-03-10
Capi Release HIGH 7.5
CVE-2016-9882

An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs …

Fix: after 249
Fix from $1,950 2017-01-13
Cloud Foundry Uaa Bosh HIGH 8.1
CVE-2016-6659

Cloud Foundry before 248; UAA 2.x before 2.7.4.12, 3.x before 3.6.5, and 3.7.x through 3.9.x before 3.9.3; and UAA bosh release (aka uaa-release) bef…

Fix: after 247.0
Fix from $1,950 2016-12-23
Cloud Foundry Uaa Bosh HIGH 8.8
CVE-2016-6651

The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5; UAA BOSH…

Fix: after 242.0
Fix from $1,950 2016-09-30
Cloud Foundry Uaa Bosh CRITICAL 9.6
CVE-2016-6637

Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and…

Fix: after 241
Fix from $2,300 2016-09-30
Cloud Foundry Uaa Bosh MEDIUM 5.3
CVE-2016-6636

The OAuth authorization implementation in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3.0.5, and 3.4.x before 3.4.4;…

Fix: after 241
Fix from $1,600 2016-09-30
Php Buildpack HIGH 7.5
CVE-2016-6639

Cloud Foundry PHP Buildpack (aka php-buildpack) before 4.3.18 and PHP Buildpack Cf-release before 242, as used in Pivotal Cloud Foundry (PCF) Elastic…

Fix: after 4.3.17
Fix from $1,950 2016-09-18