VendorsCloud Foundrycapi-releaseany version
Vulnerabilities

Cloud Foundry Cloudfoundry CAPI-release any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

19CVEs
CVE-2020-5417
Cloud Controller may allow developers to claim sensitive routes
Published 2020-08-21 · Modified
8.8EPSS 0.010
CVE-2018-1195
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an access token, either due to lack of client credentials or revocation, would allow authentication.
Published 2018-03-19 · Modified
8.8EPSS 0.010
CVE-2019-3785
Cloud Controller provides signed URL with write authorization to read only user
Published 2019-03-13 · Modified
8.1EPSS 0.013
CVE-2018-1266
Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on the Cloud Controller instance.
Published 2018-03-27 · Modified
8.1EPSS 0.011
CVE-2023-20881
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.
Published 2023-05-19 · Modified
8.1EPSS 0.004
CVE-2020-5400
Cloud Controller logs environment variables from app manifests
Published 2020-02-27 · Modified
8.0EPSS 0.008
CVE-2020-5423
Cloud Controller is vulnerable to denial of service via YAML parsing
Published 2020-12-02 · Modified
7.8EPSS 0.011
CVE-2017-8033
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted application that can write arbitrary files to the Cloud Controller VM.
Published 2017-07-25 · Modified
7.8EPSS 0.010
CVE-2016-9882
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v250 and CAPI-release versions prior to v1.12.0. Cloud Foundry logs the credentials returned from service brokers in Cloud Controller system component logs. These logs are written to disk and often sent to a log aggregator via syslog.
Published 2017-01-13 · Modified
7.5EPSS 0.017
CVE-2017-8035
An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for that installation.
Published 2017-07-25 · Modified
7.5EPSS 0.014
CVE-2019-3798
Escalation of Privileges in Cloud Controller
Published 2019-04-17 · Modified
7.5EPSS 0.013
CVE-2021-22101
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2017-8034
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Published 2017-07-17 · Modified
6.6EPSS 0.008
CVE-2016-8219
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause application downtime if the restage fails.
Published 2017-06-13 · Modified
6.5EPSS 0.010
CVE-2017-14389
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover."
Published 2017-11-28 · Modified
6.5EPSS 0.009
CVE-2021-22115
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.
Published 2021-04-08 · Modified
6.5EPSS 0.008
CVE-2016-2169
Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service.
Published 2018-04-18 · Modified
5.3EPSS 0.010
CVE-2021-22100
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.
Published 2022-03-25 · Modified
5.3EPSS 0.009
CVE-2020-5418
Cloud Controller allows users with no roles to list droplets
Published 2020-09-03 · Modified
4.3EPSS 0.006