Записи Cloud Foundry
9 опубликованных записей вендора cloud foundry.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-19 Data Processing Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-214 Invocation of Process Using Visible Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-284 Improper Access Control1
- CWE-354 Improper Validation of Integrity Check Value1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
9 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
35Наблюдать | CVE-2018-15755Эксплойта нет | CF networking internal policy server SQL injectioncloud foundry · cf-networking · CWE-89 | Высокая8,8 | — | 1,3 % | 12 окт. 2018 г. |
35Наблюдать | CVE-2017-4961Эксплойта нет | An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.cloud foundry · bosh · CWE-354 | Высокая8,8 | — | 0,5 % | 13 июн. 2017 г. |
32Наблюдать | CVE-2018-11083Эксплойта нет | Bosh accepts refresh tokens in place of an access tokencloud foundry · bosh | Высокая8,1 | — | 1,5 % | 5 окт. 2018 г. |
31Наблюдать | CVE-2019-11271Эксплойта нет | Bosh Deployment logs leak sensitive informationcloud foundry · bosh · CWE-532 | Высокая7,8 | — | 0,3 % | 18 июн. 2019 г. |
30Наблюдать | CVE-2016-3091Эксплойта нет | Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.cloud foundry · diego · CWE-19 | Высокая7,5 | — | 1,2 % | 8 июн. 2017 г. |
27Наблюдать | CVE-2018-15800Эксплойта нет | Timing attack allows extraction of signing key in Bits Servicecloud foundry · bits service · CWE-200 | Средняя6,8 | — | 0,9 % | 10 дек. 2018 г. |
27Наблюдать | CVE-2026-41704Эксплойта нет | Compromised VM can make arbitrary blobstore deletescloud foundry · bosh · CWE-284 | Средняя6,8 | — | 0,1 % | 27 мая 2026 г. |
26Наблюдать | CVE-2020-5422Эксплойта нет | UAA password may appear in BOSH System Metrics Server process argumentscloud foundry · bosh system metrics server · CWE-214 | Средняя6,5 | — | 0,9 % | 2 окт. 2020 г. |
17Наблюдать | CVE-2026-41009Эксплойта нет | Local Blobstore may allow arbitrary reads/deletescloud foundry · bosh · CWE-22 | Средняя4,3 | — | 0,1 % | 27 мая 2026 г. |
- CVE-2018-1575535Наблюдать
CF networking internal policy server SQL injection
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloud foundry · cf-networking12 окт. 2018 г.
- CVE-2017-496135Наблюдать
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.
ВысокаяCVSS 8,8Эксплойта нетEPSS 0 %cloud foundry · bosh13 июн. 2017 г.
- CVE-2018-1108332Наблюдать
Bosh accepts refresh tokens in place of an access token
ВысокаяCVSS 8,1Эксплойта нетEPSS 1 %cloud foundry · bosh5 окт. 2018 г.
- CVE-2019-1127131Наблюдать
Bosh Deployment logs leak sensitive information
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %cloud foundry · bosh18 июн. 2019 г.
- CVE-2016-309130Наблюдать
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %cloud foundry · diego8 июн. 2017 г.
- CVE-2018-1580027Наблюдать
Timing attack allows extraction of signing key in Bits Service
СредняяCVSS 6,8Эксплойта нетEPSS 1 %cloud foundry · bits service10 дек. 2018 г.
- CVE-2026-4170427Наблюдать
Compromised VM can make arbitrary blobstore deletes
СредняяCVSS 6,8Эксплойта нетEPSS 0 %cloud foundry · bosh27 мая 2026 г.
- CVE-2020-542226Наблюдать
UAA password may appear in BOSH System Metrics Server process arguments
СредняяCVSS 6,5Эксплойта нетEPSS 1 %cloud foundry · bosh system metrics server2 окт. 2020 г.
- CVE-2026-4100917Наблюдать
Local Blobstore may allow arbitrary reads/deletes
СредняяCVSS 4,3Эксплойта нетEPSS 0 %cloud foundry · bosh27 мая 2026 г.