CVE-2015-5173
- EPSS 0.48%
- Veröffentlicht 24.10.2017 17:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Refere...
CVE-2017-8048
- EPSS 0.42%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on t...
CVE-2017-8047
- EPSS 0.2%
- Veröffentlicht 04.10.2017 01:29:03
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker ...
CVE-2016-0732
- EPSS 0.41%
- Veröffentlicht 07.09.2017 13:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users ...
CVE-2016-0713
- EPSS 0.24%
- Veröffentlicht 31.08.2017 14:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
CVE-2017-8037
- EPSS 0.38%
- Veröffentlicht 21.08.2017 22:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035 you should also upgra...
CVE-2017-8033
- EPSS 0.21%
- Veröffentlicht 25.07.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space deve...
CVE-2017-8035
- EPSS 0.38%
- Veröffentlicht 25.07.2017 04:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can ...
CVE-2017-8034
- EPSS 0.47%
- Veröffentlicht 17.07.2017 14:29:01
- Zuletzt bearbeitet 20.04.2025 01:37:25
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain ...
CVE-2016-8218
- EPSS 0.59%
- Veröffentlicht 13.06.2017 06:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other user...