Cloud Foundry cf-Deployment 27.4.0

CPE Details

Cloud Foundry cf-Deployment 27.4.0
27.4.0
2023-09-26
11h46 +00:00
2023-09-26
11h46 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cloudfoundry:cf-deployment:27.4.0:*:*:*:*:*:*:*

Informations

Vendor

cloudfoundry

Product

cf-deployment

Version

27.4.0

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2023-34041 2023-09-08 07h22 +00:00 Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.
5.3
Medium
CVE-2023-20882 2023-05-25 22h00 +00:00 In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and removes it from the routing pool.
5.9
Medium
CVE-2023-20881 2023-05-18 22h00 +00:00 Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may override other users syslog drain credentials if they're aware of the client certificate used for that syslog drain. This applies even if the drain has zero certs. This would allow the user to override the private key and add or modify a certificate authority used for the connection.
8.1
High