Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2026-47829 Argument Injection in bosh-cli allows a compromised BOSH Director to inject arbitrary OpenSSH options into the locally-spawned ssh process when an op… Bosh Cli 7.10.4+ Fix from $1,9502026-07-09 CRITICAL 9.1 CVE-2026-47826 The blobs.yml path key traversal vulnerability in the BOSH CLI tool allows an attacker to write arbitrary files and exfiltrate sensitive information.… Bosh Cli 7.10.4+ Fix from $2,3002026-07-09 HIGH 8.8 CVE-2026-47828 During bosh create-env and bosh delete-env, the CLI uploads compiled CPI packages and rendered job templates to the new VM's DAV blobstore over HTTPS… Bosh Cli 7.10.4+ Fix from $1,9502026-07-09 HIGH 7.8 CVE-2026-41857 A compromised or malicious BOSH Director can execute arbitrary shell commands on the operator's workstation when the operator runs bosh ssh (or bosh … Bosh Cli 7.10.5+ Fix from $1,9502026-07-09 MEDIUM 5.0 CVE-2026-22726 Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious dev… Cf Deployment 0.372.0 / 55.0.0+ Fix from $1,6002026-05-01 MEDIUM 6.5 CVE-2026-22723 Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and … Cf Deployment 78.8.0+ Fix from $1,6002026-03-05 HIGH 7.5 CVE-2025-22246 Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. Cf Deployment 49.0.0 / 77.32.0+ Fix from $1,9502025-05-13 HIGH 7.5 CVE-2024-22279 Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability o… Cf Deployment after 40.13.0 Fix from $1,9502024-06-10 MEDIUM 5.3 CVE-2023-34041 Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this … Cf Deployment 0.278.0 / 32.4.0+ Fix from $1,6002023-09-08 MEDIUM 5.9 CVE-2023-20882 In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applicat… Cf Deployment 0.266.0 / 29.0.0+ Fix from $1,6002023-05-26 HIGH 8.1 CVE-2023-20881 Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credenti… Capi Release after 29.0.0 Fix from $1,9502023-05-19 CRITICAL 9.1 CVE-2022-31733 Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on d… Cf Deployment after 23.2.0 Fix from $2,3002023-02-03 CRITICAL 9.1 CVE-2018-25046 Due to improper path sanitization, archives containing relative file paths can cause files to be written (or overwritten) outside of the target direc… Archiver 2018-05-23+ Fix from $2,3002022-12-27 MEDIUM 5.3 CVE-2021-22100 In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or malici… Capi Release 1.122.0 / 17.1.0+ Fix from $1,6002022-03-25 HIGH 7.5 CVE-2021-22101 Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers … Capi Release 1.118.0 / 16.24.0+ Fix from $1,9502021-10-27 MEDIUM 6.1 CVE-2021-22098 UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by… Cf Deployment 16.20.0 / 75.5.0+ Fix from $1,6002021-08-11 HIGH 7.5 CVE-2021-22001 In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an iden… Cf Deployment 16.18.0 / 75.3.0+ Fix from $1,9502021-07-22 MEDIUM 6.5 CVE-2021-22115 Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI datab… Capi Release 1.106.0 / 16.2.0+ Fix from $1,6002021-04-08 HIGH 7.5 CVE-2020-5423 CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can sen… Capi Release 1.101.0 / 15.0.0+ Fix from $1,9502020-12-02 HIGH 7.7 CVE-2020-5420 Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF clu… Cf Deployment 0.206.0 / 13.15.0+ Fix from $1,9502020-09-03 HIGH 8.8 CVE-2020-5417 Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is tr… Capi Release 1.97.0 / 13.12.0+ Fix from $1,9502020-08-21 MEDIUM 6.5 CVE-2020-5416 Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is poten… Cf Deployment 0.204.0 / 13.13.0+ Fix from $1,6002020-08-21 HIGH 8.8 CVE-2020-5402 In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked in the callback func… Cf Deployment 12.33.0 / 74.14.0+ Fix from $1,9502020-02-27 MEDIUM 6.5 CVE-2020-5400 Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive in… Capi Release 1.91.0 / 12.33.0+ Fix from $1,6002020-02-27 MEDIUM 5.3 CVE-2020-5401 Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching … Routing Release 0.197.0+ Fix from $1,6002020-02-27 HIGH 7.4 CVE-2020-5399 Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with acce… Credhub 2.5.10 / 12.29.0+ Fix from $1,9502020-02-12 MEDIUM 6.5 CVE-2019-11293 Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter… Cf Deployment 12.12.0 / 74.10.0+ Fix from $1,6002019-12-06 HIGH 7.5 CVE-2019-11290 Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide … Cf Deployment 12.10.0 / 74.8.0+ Fix from $1,9502019-11-26 HIGH 8.6 CVE-2019-11289 Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HT… Cf Deployment 0.193.0 / 12.8.0+ Fix from $1,9502019-11-19 HIGH 8.8 CVE-2019-11283 Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volu… Cf Deployment 2.0.3 / 12.2.0+ Fix from $1,9502019-10-23