Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service.
2018-04-18T16:29:00.213
2024-11-21T02:47:56.963
Modified
CVSSv3.0: 5.3 (MEDIUM)
AV:N/AC:L/Au:N/C:N/I:P/A:N
10.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | capi-release | < 1.0.0 | Yes |
Hardware | cloudfoundry | cloud_controller | - | No |
Application | cloudfoundry | cf-release | < 237 | Yes |
Hardware | cloudfoundry | cloud_controller | - | No |