Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Cloud Foundry Deployment HIGH 7.5
CVE-2023-34061

Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerabil…

Fix: after 33.5.0
Fix from $1,950 2024-01-12
Reactor Netty HIGH 7.5
CVE-2023-34054

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, it is possible for a user to provide specially craft…

Fix: 1.0.39 / 1.1.13+
Fix from $1,950 2023-11-28
Reactor Netty HIGH 7.5
CVE-2023-34062

In Reactor Netty HTTP Server, versions 1.1.x prior to 1.1.13 and versions 1.0.x prior to 1.0.39, a malicious user can send a request using a speciall…

Fix: 1.0.39 / 1.1.13+
Fix from $1,950 2023-11-15
Cloud Foundry Nfs Volume MEDIUM 6.5
CVE-2023-20885

Vulnerability in Cloud Foundry Notifications, Cloud Foundry SMB-volume release, Cloud FOundry cf-nfs-volume release.This issue affects Notifications:…

Fix: 3.1.19 / 5.0.27+
Fix from $1,600 2023-06-16
Spring Security Oauth MEDIUM 6.5
CVE-2022-22969

<Issue Description> Spring Security OAuth versions 2.5.x prior to 2.5.2 and older unsupported versions are susceptible to a Denial-of-Service (DoS) a…

Fix: 2.4.2 / 2.5.2+
Fix from $1,600 2022-04-21
Reactor Netty HIGH 7.5
CVE-2020-5403

Reactor Netty HttpServer, versions 0.9.3 and 0.9.4, is exposed to a URISyntaxException that causes the connection to be closed prematurely instead of…

Mitigation only
Fix from $1,950 2020-03-03
Reactor Netty MEDIUM 5.9
CVE-2020-5404

The HttpClient from Reactor Netty, versions 0.9.x prior to 0.9.5, and versions 0.8.x prior to 0.8.16, may be used incorrectly, leading to a credentia…

Fix: after 0.9.4
Fix from $1,600 2020-03-03
Tc Runtimes HIGH 7.0
CVE-2019-11288

In Pivotal tc Server, 3.x versions prior to 3.2.19 and 4.x versions prior to 4.0.10, and Pivotal tc Runtimes, 7.x versions prior to 7.0.99.B, 8.x ver…

Fix: 3.2.19 / 4.0.10+
Fix from $1,950 2020-01-27
Reactor Netty HIGH 8.6
CVE-2019-11284

Pivotal Reactor Netty, versions prior to 0.8.11, passes headers through redirects, including authorization ones. A remote unauthenticated malicious u…

Fix: 0.8.11+
Fix from $1,950 2019-10-17
Cloud Foundry Container Runtime HIGH 8.8
CVE-2018-1223

Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user …

Fix: 0.14.0+
Fix from $1,950 2018-09-17
Spring Flex HIGH 8.1
CVE-2017-3203EPSS 6%

The Java implementations of AMF3 deserializers in Pivotal/Spring Spring-flex derive class instances from java.io.Externalizable rather than the AMF3 …

No fix yet
Fix from $1,950 2018-06-11
Spring Web Flow MEDIUM 5.9
CVE-2017-8039

An issue was discovered in Pivotal Spring Web Flow through 2.4.5. Applications that do not change the value of the MvcViewFactoryCreator useSpringBin…

Mitigation only
Fix from $1,600 2017-11-27
Pcf Tile Generator HIGH 7.5
CVE-2017-4975

An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security…

Fix: after 5.0.7
Fix from $1,950 2017-06-13
Spring Web Flow MEDIUM 5.9
CVE-2017-4971EPSS 16%

An issue was discovered in Pivotal Spring Web Flow through 2.4.4. Applications that do not change the value of the MvcViewFactoryCreator useSpringBin…

Patch available
Fix from $1,600 2017-06-13
Bosh Stemcell CRITICAL 9.0
CVE-2016-4435

An endpoint of the Agent running on the BOSH Director VM with stemcell versions prior to 3232.6 and 3146.13 may allow unauthenticated clients to read…

Fix: after 3232.4
Fix from $2,300 2017-05-25
Spring Security Oauth HIGH 8.8
CVE-2016-4977EPSS 79%

When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type param…

Mitigation only
Fix from $1,950 2017-05-25
Operations Manager CRITICAL 9.8
CVE-2016-0930

Pivotal Cloud Foundry (PCF) Ops Manager before 1.6.19 and 1.7.x before 1.7.10, when vCloud or vSphere is used, has a default password for compilation…

Fix: after 1.6.18
Fix from $2,300 2016-09-18
Cloud Foundry Elastic Runtime HIGH 7.4
CVE-2016-0928

Multiple open redirect vulnerabilities in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.30 and 1.7.x before 1.7.8 allow remote attackers to …

Fix: after 1.6.29
Fix from $1,950 2016-09-18