Cloud Foundry kayıtları
cloud foundry üreticisine ait 9 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 0
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-19 Data Processing Errors1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-214 Invocation of Process Using Visible Sensitive Information1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-284 Improper Access Control1
- CWE-354 Improper Validation of Integrity Check Value1
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
9 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
35İzleyin | CVE-2018-15755İstismar yok | CF networking internal policy server SQL injectioncloud foundry · cf-networking · CWE-89 | Yüksek8,8 | — | %1,3 | 12 Eki 2018 |
35İzleyin | CVE-2017-4961İstismar yok | An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.cloud foundry · bosh · CWE-354 | Yüksek8,8 | — | %0,5 | 13 Haz 2017 |
32İzleyin | CVE-2018-11083İstismar yok | Bosh accepts refresh tokens in place of an access tokencloud foundry · bosh | Yüksek8,1 | — | %1,5 | 5 Eki 2018 |
31İzleyin | CVE-2019-11271İstismar yok | Bosh Deployment logs leak sensitive informationcloud foundry · bosh · CWE-532 | Yüksek7,8 | — | %0,3 | 18 Haz 2019 |
30İzleyin | CVE-2016-3091İstismar yok | Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.cloud foundry · diego · CWE-19 | Yüksek7,5 | — | %1,2 | 8 Haz 2017 |
27İzleyin | CVE-2018-15800İstismar yok | Timing attack allows extraction of signing key in Bits Servicecloud foundry · bits service · CWE-200 | Orta6,8 | — | %0,9 | 10 Ara 2018 |
27İzleyin | CVE-2026-41704İstismar yok | Compromised VM can make arbitrary blobstore deletescloud foundry · bosh · CWE-284 | Orta6,8 | — | %0,1 | 27 May 2026 |
26İzleyin | CVE-2020-5422İstismar yok | UAA password may appear in BOSH System Metrics Server process argumentscloud foundry · bosh system metrics server · CWE-214 | Orta6,5 | — | %0,9 | 2 Eki 2020 |
17İzleyin | CVE-2026-41009İstismar yok | Local Blobstore may allow arbitrary reads/deletescloud foundry · bosh · CWE-22 | Orta4,3 | — | %0,1 | 27 May 2026 |
- CVE-2018-1575535İzleyin
CF networking internal policy server SQL injection
YüksekCVSS 8,8İstismar yokEPSS %1cloud foundry · cf-networking12 Eki 2018
- CVE-2017-496135İzleyin
An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions.
YüksekCVSS 8,8İstismar yokEPSS %0cloud foundry · bosh13 Haz 2017
- CVE-2018-1108332İzleyin
Bosh accepts refresh tokens in place of an access token
YüksekCVSS 8,1İstismar yokEPSS %1cloud foundry · bosh5 Eki 2018
- CVE-2019-1127131İzleyin
Bosh Deployment logs leak sensitive information
YüksekCVSS 7,8İstismar yokEPSS %0cloud foundry · bosh18 Haz 2019
- CVE-2016-309130İzleyin
Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.
YüksekCVSS 7,5İstismar yokEPSS %1cloud foundry · diego8 Haz 2017
- CVE-2018-1580027İzleyin
Timing attack allows extraction of signing key in Bits Service
OrtaCVSS 6,8İstismar yokEPSS %1cloud foundry · bits service10 Ara 2018
- CVE-2026-4170427İzleyin
Compromised VM can make arbitrary blobstore deletes
OrtaCVSS 6,8İstismar yokEPSS %0cloud foundry · bosh27 May 2026
- CVE-2020-542226İzleyin
UAA password may appear in BOSH System Metrics Server process arguments
OrtaCVSS 6,5İstismar yokEPSS %1cloud foundry · bosh system metrics server2 Eki 2020
- CVE-2026-4100917İzleyin
Local Blobstore may allow arbitrary reads/deletes
OrtaCVSS 4,3İstismar yokEPSS %0cloud foundry · bosh27 May 2026