Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-1269


Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not handle errors thrown while constructing certain http requests. A remote authenticated user may construct malicious requests to cause the traffic controller to leave dangling TCP connections, which could cause denial of service.


Published

2018-06-06T20:29:00.550

Last Modified

2024-11-21T03:59:30.360

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 6.5 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-755

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application cloudfoundry loggregator < 89.5 Yes
Application cloudfoundry loggregator < 96.1 Yes
Application cloudfoundry loggregator < 99.1 Yes
Application cloudfoundry loggregator < 101.9 Yes
Application cloudfoundry loggregator < 102.2 Yes

References