Перейти к содержимому
Noroxi

Записи Cloudfoundry

116 опубликованных записей вендора cloudfoundry.

Профиль для исследователя

Попали в KEV
0 · 0 %
С эксплойтом
0 · 0 %
Pre-auth RCE
2
С записью об исправлении
22,4 %
Медиана: публикация → KEV
Ни одна запись не попала в KEV

Все записи

116 записей
  • CVE-2016-6655
    40В плане

    An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.

    КритическаяCVSS 9,8Эксплойта нетEPSS 3 %

    cloudfoundry · cf-mysql-release13 июн. 2017 г.

  • CVE-2016-0761
    39Наблюдать

    Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container

    КритическаяCVSS 9,8Эксплойта нетEPSS 2 %

    cloudfoundry · garden linux25 мая 2017 г.

  • CVE-2016-8218
    39Наблюдать

    An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release13 июн. 2017 г.

  • CVE-2015-5172
    39Наблюдать

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release24 окт. 2017 г.

  • CVE-2017-4992
    39Наблюдать

    An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x ve

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release13 июн. 2017 г.

  • CVE-2015-5171
    39Наблюдать

    The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release24 окт. 2017 г.

  • CVE-2019-3801
    39Наблюдать

    Java Projects using HTTP to fetch dependencies

    КритическаяCVSS 9,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-deployment25 апр. 2019 г.

  • CVE-2016-6658
    38Наблюдать

    Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpa

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release29 мар. 2018 г.

  • CVE-2016-6637
    38Наблюдать

    Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3

    КритическаяCVSS 9,6Эксплойта нетEPSS 1 %

    cloudfoundry · cloud foundry uaa bosh29 сент. 2016 г.

  • CVE-2016-4468
    36Наблюдать

    SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; U

    ВысокаяCVSS 8,8Proof of conceptEPSS 2 %

    cloudfoundry · cloud foundry uaa bosh11 апр. 2017 г.

  • CVE-2016-6651
    36Наблюдать

    The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;

    ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %

    cloudfoundry · cloud foundry uaa bosh29 сент. 2016 г.

  • CVE-2018-25046
    36Наблюдать

    Path traversal in code.cloudfoundry.org/archiver

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    cloudfoundry · archiver27 дек. 2022 г.

  • CVE-2024-37082
    36Наблюдать

    When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP

    КритическаяCVSS 9,1Эксплойта нетEPSS 1 %

    cloud foundry · haproxy-boshrelease3 июл. 2024 г.

  • CVE-2022-31733
    36Наблюдать

    Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another

    КритическаяCVSS 9,1Эксплойта нетEPSS 0 %

    cloudfoundry · cf-deployment3 февр. 2023 г.

  • CVE-2019-11283
    35Наблюдать

    Password leak in smbdriver logs

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-deployment23 окт. 2019 г.

  • CVE-2019-3780
    35Наблюдать

    Cloud Foundry Container Runtime Leaks IAAS Credentials

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · container runtime8 мар. 2019 г.

  • CVE-2019-11278
    35Наблюдать

    Privilege Escalation via Blind SCIM Injection in UAA

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · user account and authentication26 сент. 2019 г.

  • CVE-2019-11279
    35Наблюдать

    Privilege Escalation via Scope Manipulation in UAA

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · uaa release26 сент. 2019 г.

  • CVE-2019-3781
    35Наблюдать

    CF CLI does not sanitize user's password in verbose/trace/debug

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · command line interface7 мар. 2019 г.

  • CVE-2016-0732
    35Наблюдать

    The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when config

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    pivotal · elastic runtime7 сент. 2017 г.

  • CVE-2017-4973
    35Наблюдать

    An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x ve

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · cloud foundry uaa bosh13 июн. 2017 г.

  • CVE-2015-5173
    35Наблюдать

    Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-release24 окт. 2017 г.

  • CVE-2020-5417
    35Наблюдать

    Cloud Controller may allow developers to claim sensitive routes

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · capi-release21 авг. 2020 г.

  • CVE-2018-1195
    35Наблюдать

    In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · capi-release19 мар. 2018 г.

  • CVE-2018-1191
    35Наблюдать

    Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    cloudfoundry · cf-deployment29 мар. 2018 г.