Cloud Foundry / CF-Release
35 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2016-0708 | Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to envi… | MEDIUM | 5.9 | Jul 11, 2018 |
| CVE-2016-2169 | Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application devel… | MEDIUM | 5.3 | Apr 18, 2018 |
| CVE-2016-6658 | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is… | CRITICAL | 9.6 | Mar 29, 2018 |
| CVE-2018-1195 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tok… | HIGH | 8.8 | Mar 19, 2018 |
| CVE-2018-1190 | An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions… | MEDIUM | 6.1 | Jan 4, 2018 |
| CVE-2017-14389 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (al… | MEDIUM | 6.5 | Nov 28, 2017 |
| CVE-2017-8031 | An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4,… | MEDIUM | 5.3 | Nov 27, 2017 |
| CVE-2015-5173 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified… | HIGH | 8.8 | Oct 24, 2017 |
| CVE-2015-5172 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified… | CRITICAL | 9.8 | Oct 24, 2017 |
| CVE-2015-5171 | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.… | CRITICAL | 9.8 | Oct 24, 2017 |
| CVE-2015-5170 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct c… | HIGH | 8.8 | Oct 24, 2017 |
| CVE-2017-8048 | In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-803… | HIGH | 7.8 | Oct 3, 2017 |
| CVE-2017-8047 | In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to appen… | MEDIUM | 6.1 | Oct 3, 2017 |
| CVE-2016-0732 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple… | HIGH | 8.8 | Sep 7, 2017 |
| CVE-2016-0713 | Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to… | MEDIUM | 4.7 | Aug 31, 2017 |
| CVE-2017-8037 | In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplet… | HIGH | 7.5 | Aug 21, 2017 |
| CVE-2017-8035 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions… | HIGH | 7.5 | Jul 25, 2017 |
| CVE-2017-8033 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A… | HIGH | 7.8 | Jul 25, 2017 |
| CVE-2017-8034 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions… | MEDIUM | 6.6 | Jul 17, 2017 |
| CVE-2017-4992 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.… | CRITICAL | 9.8 | Jun 13, 2017 |
| CVE-2017-4991 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.… | HIGH | 7.2 | Jun 13, 2017 |
| CVE-2017-4974 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.… | MEDIUM | 6.5 | Jun 13, 2017 |
| CVE-2017-4972 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.… | HIGH | 7.5 | Jun 13, 2017 |
| CVE-2017-4970 | An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static fi… | MEDIUM | 5.9 | Jun 13, 2017 |
| CVE-2016-8219 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor ro… | MEDIUM | 6.5 | Jun 13, 2017 |
Showing 1 to 25 of 35 CVEs