CVE-2016-0708
- EPSS 0.22%
- Veröffentlicht 11.07.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 02:42:13
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must h...
CVE-2016-2169
- EPSS 0.24%
- Veröffentlicht 18.04.2018 16:29:00
- Zuletzt bearbeitet 21.11.2024 02:47:56
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route an...
CVE-2016-6658
- EPSS 0.31%
- Veröffentlicht 29.03.2018 22:29:00
- Zuletzt bearbeitet 21.11.2024 02:56:34
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access...
CVE-2018-1195
- EPSS 0.27%
- Veröffentlicht 19.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where...
CVE-2018-1190
- EPSS 0.22%
- Veröffentlicht 04.01.2018 06:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:21
An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack i...
CVE-2017-14389
- EPSS 0.18%
- Veröffentlicht 28.11.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from cr...
CVE-2017-8031
- EPSS 0.42%
- Veröffentlicht 27.11.2017 10:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a par...
CVE-2015-5172
- EPSS 0.4%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links.
CVE-2015-5170
- EPSS 0.31%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by...
CVE-2015-5171
- EPSS 0.49%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessi...