CVE-2019-11294
- EPSS 0.23%
- Published 19.12.2019 20:15:12
- Last modified 21.11.2024 04:20:52
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
CVE-2019-11293
- EPSS 0.57%
- Published 06.12.2019 20:15:09
- Last modified 21.11.2024 04:20:52
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if...
CVE-2019-11290
- EPSS 0.46%
- Published 26.11.2019 00:15:11
- Last modified 21.11.2024 04:20:51
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
CVE-2019-11289
- EPSS 0.73%
- Published 19.11.2019 19:15:23
- Last modified 21.11.2024 04:20:51
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
CVE-2019-11283
- EPSS 0.49%
- Published 23.10.2019 16:15:11
- Last modified 21.11.2024 04:20:50
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing ...
CVE-2019-11282
- EPSS 0.3%
- Published 23.10.2019 16:15:11
- Last modified 21.11.2024 04:20:50
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authenticated malicious user with scim.invite scope can craft a request with malicious content which can leak information about u...
CVE-2019-11277
- EPSS 0.92%
- Published 23.09.2019 18:15:11
- Last modified 21.11.2024 04:20:50
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, fac...
CVE-2019-3801
- EPSS 0.07%
- Published 25.04.2019 21:29:00
- Last modified 21.11.2024 04:42:34
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inje...
CVE-2018-1265
- EPSS 0.68%
- Published 06.06.2018 20:29:00
- Last modified 21.11.2024 03:59:29
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell ...
CVE-2018-1193
- EPSS 0.17%
- Published 23.05.2018 15:29:00
- Last modified 21.11.2024 03:59:22
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond...