VendorsCloud Foundrycf-deploymentany version
Vulnerabilities

Cloud Foundry Cloudfoundry Cf-deployment any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

37CVEs
CVE-2019-3801
Java Projects using HTTP to fetch dependencies
Published 2019-04-25 · Modified
9.8EPSS 0.006
CVE-2022-31733
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could connect to an application that should be only reachable via mTLS, without presenting a client certificate.
Published 2023-02-03 · Modified
9.1EPSS 0.004
CVE-2019-11283
Password leak in smbdriver logs
Published 2019-10-23 · Modified
8.8EPSS 0.015
CVE-2019-11293
UAA logs all query parameters with debug logging level
Published 2019-12-06 · Modified
8.8EPSS 0.013
CVE-2019-11290
Cloud Foundry UAA logs query parameters in tomcat access file
Published 2019-11-25 · Modified
8.8EPSS 0.013
CVE-2020-5417
Cloud Controller may allow developers to claim sensitive routes
Published 2020-08-21 · Modified
8.8EPSS 0.010
CVE-2018-1195
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an access token, either due to lack of client credentials or revocation, would allow authentication.
Published 2018-03-19 · Modified
8.8EPSS 0.010
CVE-2018-1191
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
Published 2018-03-29 · Modified
8.8EPSS 0.009
CVE-2020-5402
UAA fails to check the state parameter when authenticating with external IDPs
Published 2020-02-27 · Modified
8.8EPSS 0.005
CVE-2019-11289
A forged route service request using an invalid nonce can cause the gorouter to panic and crash
Published 2019-11-19 · Modified
8.6EPSS 0.015
CVE-2019-11277
Volume Services is vulnerable to an LDAP injection attack
Published 2019-09-23 · Modified
8.4EPSS 0.017
CVE-2018-1221
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.
Published 2018-03-19 · Modified
8.1EPSS 0.012
CVE-2023-20881
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.
Published 2023-05-19 · Modified
8.1EPSS 0.004
CVE-2020-5400
Cloud Controller logs environment variables from app manifests
Published 2020-02-27 · Modified
8.0EPSS 0.008
CVE-2020-5423
Cloud Controller is vulnerable to denial of service via YAML parsing
Published 2020-12-02 · Modified
7.8EPSS 0.011
CVE-2020-5416
CF clusters with NGINX in front of them may be vulnerable to DoS
Published 2020-08-21 · Modified
7.7EPSS 0.012
CVE-2020-5420
Gorouter is vulnerable to DoS attack via invalid HTTP responses
Published 2020-09-03 · Modified
7.7EPSS 0.012
CVE-2021-22101
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.
Published 2021-10-27 · Modified
7.5EPSS 0.010
CVE-2021-22001
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion request of an identity provider( IdP) of type “oauth 1.0” was sent to UAA server.
Published 2021-07-22 · Modified
7.5EPSS 0.010
CVE-2024-22279
GoRouter Denial of Service Attack
Published 2024-06-10 · Modified
7.5EPSS 0.004
CVE-2025-22246
CVE-2025-22246 – UAA Private Key Exposure
Published 2025-05-13 · Analyzed
7.5EPSS 0.002
CVE-2018-1265
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell.
Published 2018-06-06 · Modified
7.2EPSS 0.018
CVE-2018-1262
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation.
Published 2018-05-15 · Modified
7.2EPSS 0.013
CVE-2018-1277
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell.
Published 2018-04-30 · Modified
6.5EPSS 0.011
CVE-2017-14389
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover."
Published 2017-11-28 · Modified
6.5EPSS 0.009
CVE-2021-22115
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.
Published 2021-04-08 · Modified
6.5EPSS 0.008
CVE-2026-22723
UAA User Token Revocation logic error
Published 2026-03-05 · Modified
6.5EPSS 0.002
CVE-2021-22098
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redirect vulnerability by social engineering leading to take over of victims’ accounts in certain cases along with redirection of UAA users to a malicious sites.
Published 2021-08-11 · Modified
6.1EPSS 0.007
CVE-2020-15586
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
Published 2020-07-17 · Modified
5.9EPSS 0.029
CVE-2023-20882
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and removes it from the routing pool.
Published 2023-05-26 · Modified
5.9EPSS 0.006
CVE-2018-1193
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Published 2018-05-23 · Modified
5.3EPSS 0.011
CVE-2021-22100
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.
Published 2022-03-25 · Modified
5.3EPSS 0.009
CVE-2023-34041
CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter
Published 2023-09-08 · Modified
5.3EPSS 0.004
CVE-2026-22726
Route Services Firewall Bypass
Published 2026-04-30 · Analyzed
5.0EPSS 0.002
CVE-2019-11282
UAA is vulnerable to a Blind SCIM injection leading to information disclosure
Published 2019-10-23 · Modified
4.3EPSS 0.011
CVE-2019-11294
CAPI leaks service broker URLs and GUIDs to space developers
Published 2019-12-19 · Modified
4.3EPSS 0.008
CVE-2020-5418
Cloud Controller allows users with no roles to list droplets
Published 2020-09-03 · Modified
4.3EPSS 0.006