Home/Product/cloudfoundry cf deployment
Product

cloudfoundry cf deployment

38 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2026-22726
>= 0.0.2 and < 55.0.0
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a resu
5.0MEDIUM
CVE-2026-22723
> 48.7.0 and <= 54.11.0
Inappropriate user token revocation due to a logic error in the token revocation endpoint implementation in Cloudfoundry UAA v77.
6.5MEDIUM
CVE-2025-22246
>= 45.1.0 and < 49.0.0
Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
3.0LOW
CVE-2024-22279
>= 30.9.0 and <= 40.13.0
Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the ser
5.9MEDIUM
CVE-2023-34041
< 32.4.0
Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated att
5.3MEDIUM
CVE-2023-20882
>= 27.4.0 and < 29.0.0
In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of
5.9MEDIUM
CVE-2023-20881
>= 24.7.0 and <= 29.0.0
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users sy
8.1HIGH
CVE-2022-31733
>= 17.1 and <= 23.2.0
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible vi
9.1CRITICAL
CVE-2021-22100
< 17.1.0
In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (acc
5.3MEDIUM
CVE-2021-22101
< 16.24.0
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthe
7.5HIGH
CVE-2021-22098
< 16.20.0
UAA server versions prior to 75.4.0 are vulnerable to an open redirect vulnerability. A malicious user can exploit the open redire
6.1MEDIUM
CVE-2021-22001
< 16.18.0
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in response when deletion
7.5HIGH
CVE-2021-22115
< 16.2.0
Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is
6.5MEDIUM
CVE-2020-5423
< 15.0.0
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicio
7.5HIGH
CVE-2020-5420
< 13.15.0
Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-se
7.7HIGH
CVE-2020-5418
< 13.17.0
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" s
4.3MEDIUM
CVE-2020-5417
< 13.12.0
Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system
8.8HIGH
CVE-2020-5416
< 13.13.0
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the
6.5MEDIUM
CVE-2020-15586
< 13.7.0
Go before 1.13.13 and 1.14.x before 1.14.5 has a data race in some net/http servers, as demonstrated by the httputil.ReverseProxy
5.9MEDIUM
CVE-2020-5402
< 12.33.0
In Cloud Foundry UAA, versions prior to 74.14.0, a CSRF vulnerability exists due to the OAuth2 state parameter not being checked i
8.8HIGH
CVE-2020-5400
< 12.33.0
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may i
6.5MEDIUM
CVE-2019-11294
< 12.7.0
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including s
4.3MEDIUM
CVE-2019-11293
< 12.12.0
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent a
6.5MEDIUM
CVE-2019-11290
< 12.10.0
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters
7.5HIGH
CVE-2019-11289
< 12.8.0
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious use
8.6HIGH
CVE-2019-11283
< 12.2.0
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with acc
8.8HIGH
CVE-2019-11282
< 12.2.0
Cloud Foundry UAA, versions prior to v74.3.0, contains an endpoint that is vulnerable to SCIM injection attack. A remote authentic
4.3MEDIUM
CVE-2019-11277
< 11.1.0
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection.
8.1HIGH
CVE-2019-3801
< 7.9.0
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch depende
9.8CRITICAL
CVE-2018-1265
< 1.37.0
Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote
7.2HIGH
CVE-2018-1193
< 1.27.0
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote
5.3MEDIUM
CVE-2018-1262
>= 1.27.0 and <= 1.31.0
Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across ident
7.2HIGH
CVE-2018-1277
< 1.28.0
Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote auth
6.5MEDIUM
CVE-2018-1191
< 1.9.0
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden
8.8HIGH
CVE-2018-1221
< 1.14.0
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AW
8.1HIGH
CVE-2018-1195
< 1.3.0
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud C
8.8HIGH
CVE-2017-14389
< 1.0.0
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to
6.5MEDIUM
CVE-2017-14390
all versions
In Cloud Foundry Foundation cf-deployment v0.35.0, a misconfiguration with Loggregator and syslog-drain causes logs to be drained
7.5HIGH
Vulnerabilities
CISA KEV catalog
CWE weaknesses
CAPEC attack patterns
Package vulnerabilities
Threat intelligence
Threat actors
Tools & malware
ATT&CK techniques
IOCs
Detection & defense
Sigma rules
YARA rules
Atomic Red Team tests
D3FEND countermeasures
Compliance
NIST 800-53
ISO 27001:2022
SOC 2 TSC
PCI-DSS v4.0
CIS Controls v8.1
About
All capabilities
Live statistics
Data sources
Privacy policy
Terms of service
threatengine.sh  ·  Open-source threat intelligence platform  ·  100+ authoritative sources  ·  Every fact traces to its origin