VendorsCloud Foundryrouting-releaseall versions
Vulnerabilities

Cloud Foundry Routing-release

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

8CVEs
CVE-2016-8218
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.
Published 2017-06-13 · Modified
9.8EPSS 0.013
CVE-2019-11289
A forged route service request using an invalid nonce can cause the gorouter to panic and crash
Published 2019-11-19 · Modified
8.6EPSS 0.015
CVE-2018-1221
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.
Published 2018-03-19 · Modified
8.1EPSS 0.012
CVE-2020-5416
CF clusters with NGINX in front of them may be vulnerable to DoS
Published 2020-08-21 · Modified
7.7EPSS 0.012
CVE-2017-8034
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.
Published 2017-07-17 · Modified
6.6EPSS 0.008
CVE-2020-15586
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy Handler, because it reads a request body and writes a response at the same time.
Published 2020-07-17 · Modified
5.9EPSS 0.029
CVE-2018-1193
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Published 2018-05-23 · Modified
5.3EPSS 0.011
CVE-2023-34041
CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter
Published 2023-09-08 · Modified
5.3EPSS 0.004