CVE-2016-3084
- EPSS 0.34%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnera...
CVE-2016-2165
- EPSS 0.26%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404...
CVE-2016-0781
- EPSS 0.27%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by s...
CVE-2016-0780
- EPSS 0.39%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An a...
CVE-2015-3191
- EPSS 0.12%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the change_email form in UAA is vulnerable to a CSRF attack. This allows an attacker to trigge...
CVE-2015-3190
- EPSS 0.2%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
With Cloud Foundry Runtime cf-release versions v209 or earlier, UAA Standalone versions 2.2.6 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier the UAA logout link is susceptible to an open redirect which allows an attacker to insert mali...
CVE-2015-3189
- EPSS 0.18%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
With Cloud Foundry Runtime cf-release versions v208 or earlier, UAA Standalone versions 2.2.5 or earlier and Pivotal Cloud Foundry Runtime 1.4.5 or earlier, old Password Reset Links are not expired after the user changes their current email address t...
CVE-2015-1834
- EPSS 0.3%
- Published 25.05.2017 17:29:00
- Last modified 20.04.2025 01:37:25
A path traversal vulnerability was identified in the Cloud Foundry component Cloud Controller that affects cf-release versions prior to v208 and Pivotal Cloud Foundry Elastic Runtime versions prior to 1.4.2. Path traversal is the 'outbreak' of a give...
CVE-2016-5006
- EPSS 0.33%
- Published 02.05.2017 14:59:00
- Last modified 20.04.2025 01:37:25
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
CVE-2016-5016
- EPSS 0.28%
- Published 24.04.2017 19:59:00
- Last modified 20.04.2025 01:37:25
Pivotal Cloud Foundry 239 and earlier, UAA (aka User Account and Authentication Server) 3.4.1 and earlier, UAA release 12.2 and earlier, PCF (aka Pivotal Cloud Foundry) Elastic Runtime 1.6.x before 1.6.35, and PCF Elastic Runtime 1.7.x before 1.7.13 ...