Cloudfoundry kayıtları
cloudfoundry üreticisine ait 116 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 2
- Düzeltme kaydı olan
- %22,4
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor8
- CWE-269 Improper Privilege Management7
- CWE-20 Improper Input Validation6
- CWE-400 Uncontrolled Resource Consumption6
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')5
- CWE-532 Insertion of Sensitive Information into Log File5
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
116 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
40Planlayın | CVE-2016-6655İstismar yok | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.cloudfoundry · cf-mysql-release · CWE-77 | Kritik9,8 | — | %3,4 | 13 Haz 2017 |
39İzleyin | CVE-2016-0761İstismar yok | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing containercloudfoundry · garden linux · CWE-19 | Kritik9,8 | — | %1,6 | 25 May 2017 |
39İzleyin | CVE-2016-8218İstismar yok | An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.cloudfoundry · cf-release · CWE-20 | Kritik9,8 | — | %1,3 | 13 Haz 2017 |
39İzleyin | CVE-2015-5172İstismar yok | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-640 | Kritik9,8 | — | %1,2 | 24 Eki 2017 |
39İzleyin | CVE-2017-4992İstismar yok | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x vecloudfoundry · cf-release · CWE-269 | Kritik9,8 | — | %1,2 | 13 Haz 2017 |
39İzleyin | CVE-2015-5171İstismar yok | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic cloudfoundry · cf-release · CWE-613 | Kritik9,8 | — | %1,2 | 24 Eki 2017 |
39İzleyin | CVE-2019-3801İstismar yok | Java Projects using HTTP to fetch dependenciescloudfoundry · cf-deployment · CWE-494 | Kritik9,8 | — | %0,6 | 25 Nis 2019 |
38İzleyin | CVE-2016-6658İstismar yok | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpacloudfoundry · cf-release · CWE-200 | Kritik9,6 | — | %0,9 | 29 Mar 2018 |
38İzleyin | CVE-2016-6637İstismar yok | Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3cloudfoundry · cloud foundry uaa bosh · CWE-352 | Kritik9,6 | — | %0,7 | 29 Eyl 2016 |
36İzleyin | CVE-2016-4468Kavram kanıtı | SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; Ucloudfoundry · cloud foundry uaa bosh · CWE-89 | Yüksek8,8 | — | %2,1 | 11 Nis 2017 |
36İzleyin | CVE-2016-6651İstismar yok | The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;cloudfoundry · cloud foundry uaa bosh · CWE-264 | Yüksek8,8 | — | %1,7 | 29 Eyl 2016 |
36İzleyin | CVE-2018-25046İstismar yok | Path traversal in code.cloudfoundry.org/archivercloudfoundry · archiver · CWE-22 | Kritik9,1 | — | %1,2 | 27 Ara 2022 |
36İzleyin | CVE-2024-37082İstismar yok | When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTPcloud foundry · haproxy-boshrelease · CWE-290 | Kritik9,1 | — | %0,5 | 3 Tem 2024 |
36İzleyin | CVE-2022-31733İstismar yok | Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another cloudfoundry · cf-deployment · CWE-295 | Kritik9,1 | — | %0,4 | 3 Şub 2023 |
35İzleyin | CVE-2019-11283İstismar yok | Password leak in smbdriver logscloudfoundry · cf-deployment · CWE-532 | Yüksek8,8 | — | %1,5 | 23 Eki 2019 |
35İzleyin | CVE-2019-3780İstismar yok | Cloud Foundry Container Runtime Leaks IAAS Credentialscloudfoundry · container runtime · CWE-260 | Yüksek8,8 | — | %1,4 | 8 Mar 2019 |
35İzleyin | CVE-2019-11278İstismar yok | Privilege Escalation via Blind SCIM Injection in UAAcloudfoundry · user account and authentication · CWE-77 | Yüksek8,8 | — | %1,3 | 26 Eyl 2019 |
35İzleyin | CVE-2019-11279İstismar yok | Privilege Escalation via Scope Manipulation in UAAcloudfoundry · uaa release · CWE-77 | Yüksek8,8 | — | %1,3 | 26 Eyl 2019 |
35İzleyin | CVE-2019-3781İstismar yok | CF CLI does not sanitize user's password in verbose/trace/debugcloudfoundry · command line interface · CWE-215 | Yüksek8,8 | — | %1,3 | 7 Mar 2019 |
35İzleyin | CVE-2016-0732İstismar yok | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configpivotal · elastic runtime · CWE-269 | Yüksek8,8 | — | %1,2 | 7 Eyl 2017 |
35İzleyin | CVE-2017-4973İstismar yok | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x vecloudfoundry · cloud foundry uaa bosh · CWE-269 | Yüksek8,8 | — | %1,1 | 13 Haz 2017 |
35İzleyin | CVE-2015-5173İstismar yok | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers cloudfoundry · cf-release · CWE-200 | Yüksek8,8 | — | %1,0 | 24 Eki 2017 |
35İzleyin | CVE-2020-5417İstismar yok | Cloud Controller may allow developers to claim sensitive routescloudfoundry · capi-release · CWE-732 | Yüksek8,8 | — | %1,0 | 21 Ağu 2020 |
35İzleyin | CVE-2018-1195İstismar yok | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller cloudfoundry · capi-release · CWE-613 | Yüksek8,8 | — | %1,0 | 19 Mar 2018 |
35İzleyin | CVE-2018-1191İstismar yok | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.cloudfoundry · cf-deployment · CWE-215 | Yüksek8,8 | — | %0,9 | 29 Mar 2018 |
- CVE-2016-665540Planlayın
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31.
KritikCVSS 9,8İstismar yokEPSS %3cloudfoundry · cf-mysql-release13 Haz 2017
- CVE-2016-076139İzleyin
Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container
KritikCVSS 9,8İstismar yokEPSS %2cloudfoundry · garden linux25 May 2017
- CVE-2016-821839İzleyin
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231.
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-release13 Haz 2017
- CVE-2015-517239İzleyin
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-release24 Eki 2017
- CVE-2017-499239İzleyin
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x ve
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-release13 Haz 2017
- CVE-2015-517139İzleyin
The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-release24 Eki 2017
- CVE-2019-380139İzleyin
Java Projects using HTTP to fetch dependencies
KritikCVSS 9,8İstismar yokEPSS %1cloudfoundry · cf-deployment25 Nis 2019
- CVE-2016-665838İzleyin
Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpa
KritikCVSS 9,6İstismar yokEPSS %1cloudfoundry · cf-release29 Mar 2018
- CVE-2016-663738İzleyin
Multiple cross-site request forgery (CSRF) vulnerabilities in Pivotal Cloud Foundry (PCF) before 242; UAA 2.x before 2.7.4.7, 3.x before 3.3
KritikCVSS 9,6İstismar yokEPSS %1cloudfoundry · cloud foundry uaa bosh29 Eyl 2016
- CVE-2016-446836İzleyin
SQL injection vulnerability in Pivotal Cloud Foundry (PCF) before 238; UAA 2.x before 2.7.4.4, 3.x before 3.3.0.2, and 3.4.x before 3.4.1; U
YüksekCVSS 8,8Kavram kanıtıEPSS %2cloudfoundry · cloud foundry uaa bosh11 Nis 2017
- CVE-2016-665136İzleyin
The UAA /oauth/token endpoint in Pivotal Cloud Foundry (PCF) before 243; UAA 2.x before 2.7.4.8, 3.x before 3.3.0.6, and 3.4.x before 3.4.5;
YüksekCVSS 8,8İstismar yokEPSS %2cloudfoundry · cloud foundry uaa bosh29 Eyl 2016
- CVE-2018-2504636İzleyin
Path traversal in code.cloudfoundry.org/archiver
KritikCVSS 9,1İstismar yokEPSS %1cloudfoundry · archiver27 Ara 2022
- CVE-2024-3708236İzleyin
When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP
KritikCVSS 9,1İstismar yokEPSS %1cloud foundry · haproxy-boshrelease3 Tem 2024
- CVE-2022-3173336İzleyin
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another
KritikCVSS 9,1İstismar yokEPSS %0cloudfoundry · cf-deployment3 Şub 2023
- CVE-2019-1128335İzleyin
Password leak in smbdriver logs
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · cf-deployment23 Eki 2019
- CVE-2019-378035İzleyin
Cloud Foundry Container Runtime Leaks IAAS Credentials
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · container runtime8 Mar 2019
- CVE-2019-1127835İzleyin
Privilege Escalation via Blind SCIM Injection in UAA
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · user account and authentication26 Eyl 2019
- CVE-2019-1127935İzleyin
Privilege Escalation via Scope Manipulation in UAA
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · uaa release26 Eyl 2019
- CVE-2019-378135İzleyin
CF CLI does not sanitize user's password in verbose/trace/debug
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · command line interface7 Mar 2019
- CVE-2016-073235İzleyin
The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when config
YüksekCVSS 8,8İstismar yokEPSS %1pivotal · elastic runtime7 Eyl 2017
- CVE-2017-497335İzleyin
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x ve
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · cloud foundry uaa bosh13 Haz 2017
- CVE-2015-517335İzleyin
Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · cf-release24 Eki 2017
- CVE-2020-541735İzleyin
Cloud Controller may allow developers to claim sensitive routes
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · capi-release21 Ağu 2020
- CVE-2018-119535İzleyin
In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · capi-release19 Mar 2018
- CVE-2018-119135İzleyin
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability.
YüksekCVSS 8,8İstismar yokEPSS %1cloudfoundry · cf-deployment29 Mar 2018