Cloud Foundry records
9 published records for vendor cloud foundry.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-19 Data Processing Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-214 Invocation of Process Using Visible Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-284 Improper Access Control1
- CWE-354 Improper Validation of Integrity Check Value1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2018-15755No exploit | CF networking internal policy server SQL injectioncloud foundry · cf-networking · CWE-89 | High8.8 | — | 1.3% | Oct 12, 2018 |
35Monitor | CVE-2017-4961No exploit | An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.cloud foundry · bosh · CWE-354 | High8.8 | — | 0.5% | Jun 13, 2017 |
32Monitor | CVE-2018-11083No exploit | Bosh accepts refresh tokens in place of an access tokencloud foundry · bosh | High8.1 | — | 1.5% | Oct 5, 2018 |
31Monitor | CVE-2019-11271No exploit | Bosh Deployment logs leak sensitive informationcloud foundry · bosh · CWE-532 | High7.8 | — | 0.3% | Jun 18, 2019 |
30Monitor | CVE-2016-3091No exploit | Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.cloud foundry · diego · CWE-19 | High7.5 | — | 1.2% | Jun 8, 2017 |
27Monitor | CVE-2018-15800No exploit | Timing attack allows extraction of signing key in Bits Servicecloud foundry · bits service · CWE-200 | Medium6.8 | — | 0.9% | Dec 10, 2018 |
27Monitor | CVE-2026-41704No exploit | Compromised VM can make arbitrary blobstore deletescloud foundry · bosh · CWE-284 | Medium6.8 | — | 0.1% | May 27, 2026 |
26Monitor | CVE-2020-5422No exploit | UAA password may appear in BOSH System Metrics Server process argumentscloud foundry · bosh system metrics server · CWE-214 | Medium6.5 | — | 0.9% | Oct 2, 2020 |
17Monitor | CVE-2026-41009No exploit | Local Blobstore may allow arbitrary reads/deletescloud foundry · bosh · CWE-22 | Medium4.3 | — | 0.1% | May 27, 2026 |
- CVE-2018-1575535Monitor
CF networking internal policy server SQL injection
HighCVSS 8.8No exploitEPSS 1%cloud foundry · cf-networkingOct 12, 2018
- CVE-2017-496135Monitor
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.
HighCVSS 8.8No exploitEPSS 0%cloud foundry · boshJun 13, 2017
- CVE-2018-1108332Monitor
Bosh accepts refresh tokens in place of an access token
HighCVSS 8.1No exploitEPSS 1%cloud foundry · boshOct 5, 2018
- CVE-2019-1127131Monitor
Bosh Deployment logs leak sensitive information
HighCVSS 7.8No exploitEPSS 0%cloud foundry · boshJun 18, 2019
- CVE-2016-309130Monitor
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
HighCVSS 7.5No exploitEPSS 1%cloud foundry · diegoJun 8, 2017
- CVE-2018-1580027Monitor
Timing attack allows extraction of signing key in Bits Service
MediumCVSS 6.8No exploitEPSS 1%cloud foundry · bits serviceDec 10, 2018
- CVE-2026-4170427Monitor
Compromised VM can make arbitrary blobstore deletes
MediumCVSS 6.8No exploitEPSS 0%cloud foundry · boshMay 27, 2026
- CVE-2020-542226Monitor
UAA password may appear in BOSH System Metrics Server process arguments
MediumCVSS 6.5No exploitEPSS 1%cloud foundry · bosh system metrics serverOct 2, 2020
- CVE-2026-4100917Monitor
Local Blobstore may allow arbitrary reads/deletes
MediumCVSS 4.3No exploitEPSS 0%cloud foundry · boshMay 27, 2026