Записи Cloudfoundry
116 опубликованных записей вендора cloudfoundry.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 2
- С записью об исправлении
- 22,4 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-269 Improper Privilege Management7
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-532 Insertion of Sensitive Information into Log File5
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
116 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
40В плане | CVE-2016-6655Эксплойта нет | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.cloudfoundry · cf-mysql-release · CWE-77 | Критическая9,8 | — | 3,4 % | 13 июн. 2017 г. |
39Наблюдать | CVE-2016-0761Эксплойта нет | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing containercloudfoundry · garden linux · CWE-19 | Критическая9,8 | — | 1,6 % | 25 мая 2017 г. |
39Наблюдать | CVE-2016-8218Эксплойта нет | An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.cloudfoundry · cf-release · CWE-20 | Критическая9,8 | — | 1,3 % | 13 июн. 2017 г. |
39Наблюдать | CVE-2015-5172Эксплойта нет | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-640 | Критическая9,8 | — | 1,2 % | 24 окт. 2017 г. |
39Наблюдать | CVE-2017-4992Эксплойта нет | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x vecloudfoundry · cf-release · CWE-269 | Критическая9,8 | — | 1,2 % | 13 июн. 2017 г. |
39Наблюдать | CVE-2015-5171Эксплойта нет | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Критическая9,8 | — | 1,2 % | 24 окт. 2017 г. |
39Наблюдать | CVE-2019-3801Эксплойта нет | Java Projects using HTTP to fetch dependenciescloudfoundry · cf-deployment · CWE-494 | Критическая9,8 | — | 0,6 % | 25 апр. 2019 г. |
38Наблюдать | CVE-2016-6658Эксплойта нет | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpacloudfoundry · cf-release · CWE-200 | Критическая9,6 | — | 0,9 % | 29 мар. 2018 г. |
38Наблюдать | CVE-2016-6637Эксплойта нет | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3cloudfoundry · cloud foundry uaa bosh · CWE-352 | Критическая9,6 | — | 0,7 % | 29 сент. 2016 г. |
36Наблюдать | CVE-2016-4468Proof of concept | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; Ucloudfoundry · cloud foundry uaa bosh · CWE-89 | Высокая8,8 | — | 2,1 % | 11 апр. 2017 г. |
36Наблюдать | CVE-2016-6651Эксплойта нет | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;cloudfoundry · cloud foundry uaa bosh · CWE-264 | Высокая8,8 | — | 1,7 % | 29 сент. 2016 г. |
36Наблюдать | CVE-2018-25046Эксплойта нет | Path traversal in code.cloudfoundry.org/archivercloudfoundry · archiver · CWE-22 | Критическая9,1 | — | 1,2 % | 27 дек. 2022 г. |
36Наблюдать | CVE-2024-37082Эксплойта нет | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTPcloud foundry · haproxy-boshrelease · CWE-290 | Критическая9,1 | — | 0,5 % | 3 июл. 2024 г. |
36Наблюдать | CVE-2022-31733Эксплойта нет | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another cloudfoundry · cf-deployment · CWE-295 | Критическая9,1 | — | 0,4 % | 3 февр. 2023 г. |
35Наблюдать | CVE-2019-11283Эксплойта нет | Password leak in smbdriver logscloudfoundry · cf-deployment · CWE-532 | Высокая8,8 | — | 1,5 % | 23 окт. 2019 г. |
35Наблюдать | CVE-2019-3780Эксплойта нет | Cloud Foundry Container Runtime Leaks IAAS Credentialscloudfoundry · container runtime · CWE-260 | Высокая8,8 | — | 1,4 % | 8 мар. 2019 г. |
35Наблюдать | CVE-2019-11278Эксплойта нет | Privilege Escalation via Blind SCIM Injection in UAAcloudfoundry · user account and authentication · CWE-77 | Высокая8,8 | — | 1,3 % | 26 сент. 2019 г. |
35Наблюдать | CVE-2019-11279Эксплойта нет | Privilege Escalation via Scope Manipulation in UAAcloudfoundry · uaa release · CWE-77 | Высокая8,8 | — | 1,3 % | 26 сент. 2019 г. |
35Наблюдать | CVE-2019-3781Эксплойта нет | CF CLI does not sanitize user's password in verbose/trace/debugcloudfoundry · command line interface · CWE-215 | Высокая8,8 | — | 1,3 % | 7 мар. 2019 г. |
35Наблюдать | CVE-2016-0732Эксплойта нет | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configpivotal · elastic runtime · CWE-269 | Высокая8,8 | — | 1,2 % | 7 сент. 2017 г. |
35Наблюдать | CVE-2017-4973Эксплойта нет | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x vecloudfoundry · cloud foundry uaa bosh · CWE-269 | Высокая8,8 | — | 1,1 % | 13 июн. 2017 г. |
35Наблюдать | CVE-2015-5173Эксплойта нет | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-200 | Высокая8,8 | — | 1,0 % | 24 окт. 2017 г. |
35Наблюдать | CVE-2020-5417Эксплойта нет | Cloud Controller may allow developers to claim sensitive routescloudfoundry · capi-release · CWE-732 | Высокая8,8 | — | 1,0 % | 21 авг. 2020 г. |
35Наблюдать | CVE-2018-1195Эксплойта нет | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller cloudfoundry · capi-release · CWE-613 | Высокая8,8 | — | 1,0 % | 19 мар. 2018 г. |
35Наблюдать | CVE-2018-1191Эксплойта нет | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.cloudfoundry · cf-deployment · CWE-215 | Высокая8,8 | — | 0,9 % | 29 мар. 2018 г. |
- CVE-2016-665540В плане
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %cloudfoundry · cf-mysql-release13 июн. 2017 г.
- CVE-2016-076139Наблюдать
Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %cloudfoundry · garden linux25 мая 2017 г.
- CVE-2016-821839Наблюдать
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release13 июн. 2017 г.
- CVE-2015-517239Наблюдать
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release24 окт. 2017 г.
- CVE-2017-499239Наблюдать
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x ve
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release13 июн. 2017 г.
- CVE-2015-517139Наблюдать
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release24 окт. 2017 г.
- CVE-2019-380139Наблюдать
Java Projects using HTTP to fetch dependencies
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %cloudfoundry · cf-deployment25 апр. 2019 г.
- CVE-2016-665838Наблюдать
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpa
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %cloudfoundry · cf-release29 мар. 2018 г.
- CVE-2016-663738Наблюдать
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3
КритическаяCVSS 9,6Эксплойта нетEPSS 1 %cloudfoundry · cloud foundry uaa bosh29 сент. 2016 г.
- CVE-2016-446836Наблюдать
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; U
ВысокаяCVSS 8,8Proof of conceptEPSS 2 %cloudfoundry · cloud foundry uaa bosh11 апр. 2017 г.
- CVE-2016-665136Наблюдать
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %cloudfoundry · cloud foundry uaa bosh29 сент. 2016 г.
- CVE-2018-2504636Наблюдать
Path traversal in code.cloudfoundry.org/archiver
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cloudfoundry · archiver27 дек. 2022 г.
- CVE-2024-3708236Наблюдать
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP
КритическаяCVSS 9,1Эксплойта нетEPSS 1 %cloud foundry · haproxy-boshrelease3 июл. 2024 г.
- CVE-2022-3173336Наблюдать
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %cloudfoundry · cf-deployment3 февр. 2023 г.
- CVE-2019-1128335Наблюдать
Password leak in smbdriver logs
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · cf-deployment23 окт. 2019 г.
- CVE-2019-378035Наблюдать
Cloud Foundry Container Runtime Leaks IAAS Credentials
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · container runtime8 мар. 2019 г.
- CVE-2019-1127835Наблюдать
Privilege Escalation via Blind SCIM Injection in UAA
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · user account and authentication26 сент. 2019 г.
- CVE-2019-1127935Наблюдать
Privilege Escalation via Scope Manipulation in UAA
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · uaa release26 сент. 2019 г.
- CVE-2019-378135Наблюдать
CF CLI does not sanitize user's password in verbose/trace/debug
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · command line interface7 мар. 2019 г.
- CVE-2016-073235Наблюдать
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when config
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %pivotal · elastic runtime7 сент. 2017 г.
- CVE-2017-497335Наблюдать
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x ve
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · cloud foundry uaa bosh13 июн. 2017 г.
- CVE-2015-517335Наблюдать
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · cf-release24 окт. 2017 г.
- CVE-2020-541735Наблюдать
Cloud Controller may allow developers to claim sensitive routes
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · capi-release21 авг. 2020 г.
- CVE-2018-119535Наблюдать
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · capi-release19 мар. 2018 г.
- CVE-2018-119135Наблюдать
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %cloudfoundry · cf-deployment29 мар. 2018 г.