Vulnerability index

Browse CVEs

105 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2019-11279 CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malici… Uaa Release 74.1.0+ Fix from $1,9502019-09-26 HIGH 8.8 CVE-2019-11278 CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update'… User Account And Authentication 74.1.0+ Fix from $1,9502019-09-26 HIGH 8.1 CVE-2019-11277 Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic… Cf Deployment 1.7.11 / 2.3.0+ Fix from $1,9502019-09-23 MEDIUM 6.1 CVE-2019-11274 Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that conta… User Account And Authentication 74.0.0+ Fix from $1,6002019-08-09 CRITICAL 9.8 CVE-2019-3801 Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building… Cf Deployment 1.9.10 / 2.1.3+ Fix from $2,3002019-04-25 MEDIUM 6.1 CVE-2019-3788 Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w… Uaa Release 71.0+ Fix from $1,6002019-04-25 MEDIUM 6.5 CVE-2019-3789 Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside t… Routing Release 0.188.0+ Fix from $1,6002019-04-24 HIGH 7.1 CVE-2019-3786 Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authentic… Bosh Backup And Restore 1.5.0+ Fix from $1,9502019-04-24 HIGH 7.5 CVE-2019-3798 Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut… Capi Release 1.79.0+ Fix from $1,9502019-04-17 HIGH 8.1 CVE-2019-3785 Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with… Capi Release 1.78.0+ Fix from $1,9502019-03-13 HIGH 8.8 CVE-2019-3779 Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust … Container Runtime 0.29.0+ Fix from $1,9502019-03-08 HIGH 8.8 CVE-2019-3780 Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malic… Container Runtime 0.28.0+ Fix from $1,9502019-03-08 HIGH 8.8 CVE-2019-3781 Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo… Command Line Interface 6.43.0+ Fix from $1,9502019-03-07 HIGH 8.8 CVE-2019-3783 Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secre… Stratos 2.3.0+ Fix from $1,9502019-03-07 MEDIUM 6.5 CVE-2019-3775 Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different … Uaa Release 70.0+ Fix from $1,6002019-03-07 MEDIUM 6.5 CVE-2019-3784 Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instan… Stratos 2.3.0+ Fix from $1,6002019-03-07 HIGH 7.8 CVE-2019-3782 Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persist… Credhub Cli 2.2.1+ Fix from $1,9502019-02-13 MEDIUM 6.5 CVE-2018-11084 Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authentica… Garden Runc 1.16.1+ Fix from $1,6002018-09-18 MEDIUM 5.9 CVE-2016-0708 Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limit… Cf Release after 227 Fix from $1,6002018-07-11 HIGH 7.2 CVE-2018-1265 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a… Cf Deployment 1.37.0 / 2.8.0+ Fix from $1,9502018-06-06 MEDIUM 6.8 CVE-2018-1268 Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d… Loggregator 89.5 / 96.1+ Fix from $1,6002018-06-06 MEDIUM 6.5 CVE-2018-1269 Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d… Loggregator 89.5 / 96.1+ Fix from $1,6002018-06-06 MEDIUM 5.3 CVE-2018-1193 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X… Cf Deployment 0.175.0 / 1.27.0+ Fix from $1,6002018-05-23 MEDIUM 6.5 CVE-2018-1277 Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may … Garden Runc 1.13.0 / 1.28.0+ Fix from $1,6002018-04-30 MEDIUM 5.3 CVE-2016-2169 Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An applica… Capi Release 1.0.0 / 237+ Fix from $1,6002018-04-18 CRITICAL 9.6 CVE-2016-6658 Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho… Cf Release 1.6.49 / 1.7.31+ Fix from $2,3002018-03-29 HIGH 8.8 CVE-2018-1191 Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to… Cf Deployment 1.9.0 / 1.11.0+ Fix from $1,9502018-03-29 HIGH 8.1 CVE-2018-1266 Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malici… Capi Release 1.52.0+ Fix from $1,9502018-03-27 HIGH 8.1 CVE-2018-1267 Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an appl… Silk Release 0.2.0+ Fix from $1,9502018-03-27 HIGH 8.8 CVE-2018-1195 In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts r… Capi Release 1.3.0 / 1.46.0+ Fix from $1,9502018-03-19