Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2019-11279
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malici…
Uaa Release
74.1.0+
HIGH 8.8
CVE-2019-11278
CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update'…
User Account And Authentication
74.1.0+
HIGH 8.1
CVE-2019-11277
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authentic…
Cf Deployment
1.7.11 / 2.3.0+
MEDIUM 6.1
CVE-2019-11274
Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that conta…
User Account And Authentication
74.0.0+
CRITICAL 9.8
CVE-2019-3801
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building…
Cf Deployment
1.9.10 / 2.1.3+
MEDIUM 6.1
CVE-2019-3788
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured w…
Uaa Release
71.0+
MEDIUM 6.5
CVE-2019-3789
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside t…
Routing Release
0.188.0+
HIGH 7.1
CVE-2019-3786
Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authentic…
Bosh Backup And Restore
1.5.0+
HIGH 7.5
CVE-2019-3798
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote aut…
Capi Release
1.79.0+
HIGH 8.1
CVE-2019-3785
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with…
Capi Release
1.78.0+
HIGH 8.8
CVE-2019-3779
Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust …
Container Runtime
0.29.0+
HIGH 8.8
CVE-2019-3780
Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malic…
Container Runtime
0.28.0+
HIGH 8.8
CVE-2019-3781
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remo…
Command Line Interface
6.43.0+
HIGH 8.8
CVE-2019-3783
Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secre…
Stratos
2.3.0+
MEDIUM 6.5
CVE-2019-3775
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different …
Uaa Release
70.0+
MEDIUM 6.5
CVE-2019-3784
Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instan…
Stratos
2.3.0+
HIGH 7.8
CVE-2019-3782
Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persist…
Credhub Cli
2.2.1+
MEDIUM 6.5
CVE-2018-11084
Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authentica…
Garden Runc
1.16.1+
MEDIUM 5.9
CVE-2016-0708
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limit…
Cf Release
after 227
HIGH 7.2
CVE-2018-1265
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF a…
Cf Deployment
1.37.0 / 2.8.0+
MEDIUM 6.8
CVE-2018-1268
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…
Loggregator
89.5 / 96.1+
MEDIUM 6.5
CVE-2018-1269
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, d…
Loggregator
89.5 / 96.1+
MEDIUM 5.3
CVE-2018-1193
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X…
Cf Deployment
0.175.0 / 1.27.0+
MEDIUM 6.5
CVE-2018-1277
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may …
Garden Runc
1.13.0 / 1.28.0+
MEDIUM 5.3
CVE-2016-2169
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An applica…
Capi Release
1.0.0 / 237+
CRITICAL 9.6
CVE-2016-6658
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Altho…
Cf Release
1.6.49 / 1.7.31+
HIGH 8.8
CVE-2018-1191
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to…
Cf Deployment
1.9.0 / 1.11.0+
HIGH 8.1
CVE-2018-1266
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malici…
Capi Release
1.52.0+
HIGH 8.1
CVE-2018-1267
Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an appl…
Silk Release
0.2.0+
HIGH 8.8
CVE-2018-1195
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts r…
Capi Release
1.3.0 / 1.46.0+