Cloudfoundry records
116 published records for vendor cloudfoundry.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 2
- With a fix record
- 22.4%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-269 Improper Privilege Management7
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-532 Insertion of Sensitive Information into Log File5
The weakness classes this vendor ships most often: where to look.
CWEAll records
116 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
40Plan | CVE-2016-6655No exploit | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.cloudfoundry · cf-mysql-release · CWE-77 | Critical9.8 | — | 3.4% | Jun 13, 2017 |
39Monitor | CVE-2016-0761No exploit | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing containercloudfoundry · garden linux · CWE-19 | Critical9.8 | — | 1.6% | May 25, 2017 |
39Monitor | CVE-2016-8218No exploit | An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.cloudfoundry · cf-release · CWE-20 | Critical9.8 | — | 1.3% | Jun 13, 2017 |
39Monitor | CVE-2015-5172No exploit | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-640 | Critical9.8 | — | 1.2% | Oct 24, 2017 |
39Monitor | CVE-2017-4992No exploit | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x vecloudfoundry · cf-release · CWE-269 | Critical9.8 | — | 1.2% | Jun 13, 2017 |
39Monitor | CVE-2015-5171No exploit | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Critical9.8 | — | 1.2% | Oct 24, 2017 |
39Monitor | CVE-2019-3801No exploit | Java Projects using HTTP to fetch dependenciescloudfoundry · cf-deployment · CWE-494 | Critical9.8 | — | 0.6% | Apr 25, 2019 |
38Monitor | CVE-2016-6658No exploit | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpacloudfoundry · cf-release · CWE-200 | Critical9.6 | — | 0.9% | Mar 29, 2018 |
38Monitor | CVE-2016-6637No exploit | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3cloudfoundry · cloud foundry uaa bosh · CWE-352 | Critical9.6 | — | 0.7% | Sep 29, 2016 |
36Monitor | CVE-2016-4468Proof of concept | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; Ucloudfoundry · cloud foundry uaa bosh · CWE-89 | High8.8 | — | 2.1% | Apr 11, 2017 |
36Monitor | CVE-2016-6651No exploit | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;cloudfoundry · cloud foundry uaa bosh · CWE-264 | High8.8 | — | 1.7% | Sep 29, 2016 |
36Monitor | CVE-2018-25046No exploit | Path traversal in code.cloudfoundry.org/archivercloudfoundry · archiver · CWE-22 | Critical9.1 | — | 1.2% | Dec 27, 2022 |
36Monitor | CVE-2024-37082No exploit | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTPcloud foundry · haproxy-boshrelease · CWE-290 | Critical9.1 | — | 0.5% | Jul 3, 2024 |
36Monitor | CVE-2022-31733No exploit | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another cloudfoundry · cf-deployment · CWE-295 | Critical9.1 | — | 0.4% | Feb 3, 2023 |
35Monitor | CVE-2019-11283No exploit | Password leak in smbdriver logscloudfoundry · cf-deployment · CWE-532 | High8.8 | — | 1.5% | Oct 23, 2019 |
35Monitor | CVE-2019-3780No exploit | Cloud Foundry Container Runtime Leaks IAAS Credentialscloudfoundry · container runtime · CWE-260 | High8.8 | — | 1.4% | Mar 8, 2019 |
35Monitor | CVE-2019-11278No exploit | Privilege Escalation via Blind SCIM Injection in UAAcloudfoundry · user account and authentication · CWE-77 | High8.8 | — | 1.3% | Sep 26, 2019 |
35Monitor | CVE-2019-11279No exploit | Privilege Escalation via Scope Manipulation in UAAcloudfoundry · uaa release · CWE-77 | High8.8 | — | 1.3% | Sep 26, 2019 |
35Monitor | CVE-2019-3781No exploit | CF CLI does not sanitize user's password in verbose/trace/debugcloudfoundry · command line interface · CWE-215 | High8.8 | — | 1.3% | Mar 7, 2019 |
35Monitor | CVE-2016-0732No exploit | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configpivotal · elastic runtime · CWE-269 | High8.8 | — | 1.2% | Sep 7, 2017 |
35Monitor | CVE-2017-4973No exploit | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x vecloudfoundry · cloud foundry uaa bosh · CWE-269 | High8.8 | — | 1.1% | Jun 13, 2017 |
35Monitor | CVE-2015-5173No exploit | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-200 | High8.8 | — | 1.0% | Oct 24, 2017 |
35Monitor | CVE-2020-5417No exploit | Cloud Controller may allow developers to claim sensitive routescloudfoundry · capi-release · CWE-732 | High8.8 | — | 1.0% | Aug 21, 2020 |
35Monitor | CVE-2018-1195No exploit | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller cloudfoundry · capi-release · CWE-613 | High8.8 | — | 1.0% | Mar 19, 2018 |
35Monitor | CVE-2018-1191No exploit | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.cloudfoundry · cf-deployment · CWE-215 | High8.8 | — | 0.9% | Mar 29, 2018 |
- CVE-2016-665540Plan
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.
CriticalCVSS 9.8No exploitEPSS 3%cloudfoundry · cf-mysql-releaseJun 13, 2017
- CVE-2016-076139Monitor
Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container
CriticalCVSS 9.8No exploitEPSS 2%cloudfoundry · garden linuxMay 25, 2017
- CVE-2016-821839Monitor
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-releaseJun 13, 2017
- CVE-2015-517239Monitor
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-releaseOct 24, 2017
- CVE-2017-499239Monitor
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x ve
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-releaseJun 13, 2017
- CVE-2015-517139Monitor
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-releaseOct 24, 2017
- CVE-2019-380139Monitor
Java Projects using HTTP to fetch dependencies
CriticalCVSS 9.8No exploitEPSS 1%cloudfoundry · cf-deploymentApr 25, 2019
- CVE-2016-665838Monitor
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpa
CriticalCVSS 9.6No exploitEPSS 1%cloudfoundry · cf-releaseMar 29, 2018
- CVE-2016-663738Monitor
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3
CriticalCVSS 9.6No exploitEPSS 1%cloudfoundry · cloud foundry uaa boshSep 29, 2016
- CVE-2016-446836Monitor
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; U
HighCVSS 8.8Proof of conceptEPSS 2%cloudfoundry · cloud foundry uaa boshApr 11, 2017
- CVE-2016-665136Monitor
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;
HighCVSS 8.8No exploitEPSS 2%cloudfoundry · cloud foundry uaa boshSep 29, 2016
- CVE-2018-2504636Monitor
Path traversal in code.cloudfoundry.org/archiver
CriticalCVSS 9.1No exploitEPSS 1%cloudfoundry · archiverDec 27, 2022
- CVE-2024-3708236Monitor
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP
CriticalCVSS 9.1No exploitEPSS 1%cloud foundry · haproxy-boshreleaseJul 3, 2024
- CVE-2022-3173336Monitor
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another
CriticalCVSS 9.1No exploitEPSS 0%cloudfoundry · cf-deploymentFeb 3, 2023
- CVE-2019-1128335Monitor
Password leak in smbdriver logs
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · cf-deploymentOct 23, 2019
- CVE-2019-378035Monitor
Cloud Foundry Container Runtime Leaks IAAS Credentials
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · container runtimeMar 8, 2019
- CVE-2019-1127835Monitor
Privilege Escalation via Blind SCIM Injection in UAA
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · user account and authenticationSep 26, 2019
- CVE-2019-1127935Monitor
Privilege Escalation via Scope Manipulation in UAA
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · uaa releaseSep 26, 2019
- CVE-2019-378135Monitor
CF CLI does not sanitize user's password in verbose/trace/debug
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · command line interfaceMar 7, 2019
- CVE-2016-073235Monitor
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when config
HighCVSS 8.8No exploitEPSS 1%pivotal · elastic runtimeSep 7, 2017
- CVE-2017-497335Monitor
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x ve
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · cloud foundry uaa boshJun 13, 2017
- CVE-2015-517335Monitor
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · cf-releaseOct 24, 2017
- CVE-2020-541735Monitor
Cloud Controller may allow developers to claim sensitive routes
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · capi-releaseAug 21, 2020
- CVE-2018-119535Monitor
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · capi-releaseMar 19, 2018
- CVE-2018-119135Monitor
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
HighCVSS 8.8No exploitEPSS 1%cloudfoundry · cf-deploymentMar 29, 2018