CVE-2018-1265
- EPSS 0.65%
- Veröffentlicht 06.06.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:29
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell ...
CVE-2018-1193
- EPSS 0.17%
- Veröffentlicht 23.05.2018 15:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond...
CVE-2018-1262
- EPSS 0.39%
- Veröffentlicht 15.05.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:29
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens whi...
CVE-2018-1277
- EPSS 0.52%
- Veröffentlicht 30.04.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:31
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated...
CVE-2018-1191
- EPSS 0.35%
- Veröffentlicht 29.03.2018 20:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
CVE-2018-1221
- EPSS 0.36%
- Veröffentlicht 19.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:25
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use...
CVE-2018-1195
- EPSS 0.27%
- Veröffentlicht 19.03.2018 18:29:00
- Zuletzt bearbeitet 21.11.2024 03:59:22
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where...
CVE-2017-14389
- EPSS 0.18%
- Veröffentlicht 28.11.2017 07:29:00
- Zuletzt bearbeitet 20.04.2025 01:37:25
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from cr...