Cloud Foundry CVE Vulnerabilities & CVE List (110)

Products (CPE): — CVEs: 110

Cloud Foundry vulnerability overview

Aggregates CVE and security vulnerability intelligence across all Cloud Foundry-related products, including CVSS, EPSS, publication dates, and vulnerability intelligence data.

Historical issues mainly involve vendor risk open redirect, vendor risk cross-site scripting, vendor risk csrf, and vendor risk sql injection and related problems; some flaws may lead to vendor impact unexpected behavior.

Vulnerability distribution trend (last 24 months)

Showing 4160 of 110 CVEs
CVE Summary Source Max CVSS EPSS % Published Updated
CVE-2019-3785 Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service. [email protected] 8.1 1.29% 2019-03-13 2026-06-16
CVE-2019-3780 Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account. [email protected] 8.8 1.43% 2019-03-08 2026-06-16
CVE-2019-3779 Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate leveraging the Kubernetes CSR capability to obtain a credential that could escalate privilege access to ETCD. [email protected] 8.8 0.68% 2019-03-08 2026-06-16
CVE-2019-3784 Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id. [email protected] 8.2 1.08% 2019-03-07 2026-06-16
CVE-2019-3783 Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user. [email protected] 8.8 0.92% 2019-03-07 2026-06-16
CVE-2019-3781 Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password. [email protected] 8.8 1.33% 2019-03-07 2026-06-16
CVE-2019-3775 Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. [email protected] 7.1 0.89% 2019-03-07 2026-06-16
CVE-2019-3782 Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in CredHub that are authorized to the targeted user. [email protected] 7.8 0.36% 2019-02-13 2026-06-16
CVE-2018-11084 Cloud Foundry Garden-runC release, versions prior to 1.16.1, prevents deletion of some app environments based on file attributes. A remote authenticated malicious user may create and delete apps with crafted file attributes to cause a denial of service for new app instances or scaling up of existing apps. [email protected] 6.8 1.18% 2018-09-18 2026-06-16
CVE-2016-0708 Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through the Java Buildpack detection script, and allow the serving of static content from within the deployed artifact. The default Apache Tomcat configuration in the affected java buildpack [email protected] 5.9 1.56% 2018-07-11 2026-06-16
CVE-2018-1269 Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to leave dangling TCP connections, which could cause denial of service. [email protected] 6.5 1.06% 2018-06-06 2026-06-16
CVE-2018-1268 Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app. [email protected] 6.8 1.01% 2018-06-06 2026-06-16
CVE-2018-1265 Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack that will allow a complete takeover of a Diego Cell VM and access to all apps running on that Diego Cell. [email protected] 7.2 1.77% 2018-06-06 2026-06-16
CVE-2018-1193 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections. [email protected] 5.3 1.11% 2018-05-23 2026-06-16
CVE-2018-1262 Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the impersonated zone for clients performing offline token validation. [email protected] 7.2 1.34% 2018-05-15 2026-06-16
CVE-2018-1277 Cloud Foundry Garden-runC, versions prior to 1.13.0, does not correctly enforce disc quotas for Docker image layers. A remote authenticated user may push an app with a malicious Docker image that will consume more space on a Diego cell than allocated in their quota, potentially causing a DoS against the cell. [email protected] 6.5 1.12% 2018-04-30 2026-06-16
CVE-2016-2169 Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service. [email protected] 5.3 1.00% 2018-04-18 2026-06-16
CVE-2016-6658 Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a GitHub username and password in the URL to access a private repo. Because the URL to access the buildpack is stored unencrypted, an operator with privileged access to the Cloud Con [email protected] 9.6 0.88% 2018-03-29 2026-06-16
CVE-2018-1191 Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials. [email protected] 8.8 0.93% 2018-03-29 2026-06-16
CVE-2018-1267 Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured routing policies. [email protected] 8.1 0.99% 2018-03-27 2026-06-16
cvelogic Threat Intelligence