Cloudfoundry

Cf-deployment

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.19%
  • Veröffentlicht 06.10.2026 07:06:18
  • Zuletzt bearbeitet 06.10.2026 16:00:36

Insufficient verification of data authenticity (CWE-345) in the external OIDC login callback in Cloud Foundry UAA v4.5.0 to v79.6.0 (inclusive) allows an authenticated UAA user to bypass the OAuth authorization-code exchange and establish an authenti...

  • EPSS 0.35%
  • Veröffentlicht 06.10.2026 06:54:10
  • Zuletzt bearbeitet 06.10.2026 16:00:36

Improper authentication (CWE-287) in the OAuth token endpoint in Cloud Foundry UAA allows a remote, authenticated attacker holding a valid user access token to obtain a fully-privileged client_credentials token for the OAuth client that issued it, by...

  • EPSS 0.3%
  • Veröffentlicht 25.08.2026 11:05:11
  • Zuletzt bearbeitet 28.09.2026 23:10:00

Improper handling of case sensitivity (CWE-178) in the identity zone authorization check in the Identity Zone Endpoint in Cloud Foundry UAA allows a remote authenticated attacker holding only the zones.write authority to bypass the intended restricti...

  • EPSS 0.13%
  • Veröffentlicht 09.07.2026 06:26:02
  • Zuletzt bearbeitet 09.07.2026 16:39:17

A network attacker positioned between UAA and its LDAP directory can impersonate the directory using any certificate from any trusted CA, then harvest the LDAP bind password and every end-user password sent during simple-bind authentication, and retu...

  • EPSS 0.13%
  • Veröffentlicht 11.06.2026 20:03:22
  • Zuletzt bearbeitet 12.06.2026 16:06:17

Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two SAML flows: the OAuth 2.0 SAML2 bearer grant (token endpoint) and brows...

  • EPSS 0.24%
  • Veröffentlicht 01.06.2026 17:36:47
  • Zuletzt bearbeitet 22.07.2026 07:10:00

Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the mount-option allowlist, enabling privilege escalati...

  • EPSS 0.2%
  • Veröffentlicht 30.04.2026 23:17:00
  • Zuletzt bearbeitet 04.05.2026 18:30:01

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure a route-service that would allow it to send reques...

  • EPSS 0.36%
  • Veröffentlicht 16.04.2026 23:33:43
  • Zuletzt bearbeitet 17.04.2026 15:38:09

Cloud Foundry UUA is vulnerable to a bypass that allows an attacker to obtain a token for any user and gain access to UAA-protected systems. This vulnerability exists when SAML 2.0 bearer assertions are enabled for a client, as the UAA accepts SAML 2...

  • EPSS 0.2%
  • Veröffentlicht 17.03.2026 22:45:09
  • Zuletzt bearbeitet 18.03.2026 14:52:44

Unprotected internal endpoints in Cloud Foundry Capi Release 1.226.0 and below, and CF Deployment v54.9.0 and below on all platforms allows any user who has bypassed the firewall to potentially replace droplets and therefore applications allowing the...

  • EPSS 0.22%
  • Veröffentlicht 05.03.2026 20:40:27
  • Zuletzt bearbeitet 10.05.2026 14:16:48

Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.30.0 to v78.7.0 and in Cloudfoundry Deployment v48.7.0 to v54.10.0.