CVE-2018-1262
- EPSS 0.41%
- Published 15.05.2018 20:29:00
- Last modified 21.11.2024 03:59:29
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens whi...
CVE-2018-1277
- EPSS 0.52%
- Published 30.04.2018 20:29:00
- Last modified 21.11.2024 03:59:31
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated...
CVE-2018-1191
- EPSS 0.36%
- Published 29.03.2018 20:29:00
- Last modified 21.11.2024 03:59:22
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
CVE-2018-1221
- EPSS 0.36%
- Published 19.03.2018 18:29:00
- Last modified 21.11.2024 03:59:25
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use...
CVE-2018-1195
- EPSS 0.27%
- Published 19.03.2018 18:29:00
- Last modified 21.11.2024 03:59:22
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where...
CVE-2017-14389
- EPSS 0.18%
- Published 28.11.2017 07:29:00
- Last modified 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from cr...