MEDIUM🇬🇧 English

CVE-2020-5401

CVSS 5.3v3.1pub. 2020-02-27upd. 2024-11-21

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
  • Cloudfoundry Routing Release

    APP
    Cloudfoundry
    < 0.197.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2026-22726MEDIUM5.0ten sam produkt

Route Services mogą być wykorzystane do kierowania ruchu aplikacji do miejsc docelowych w sieci poza skonfigur...

CVE-2024-22279MEDIUM5.9ten sam produkt

Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker...

CVE-2023-20882MEDIUM5.9ten sam produkt

In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can ...

CVE-2019-3789MEDIUM6.5ten sam produkt

Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the tra...

CVE-2022-31733CRITICAL9.1PL ✓ten sam vendor

Cloudfoundry Diego — pominięcie uwierzytelniania mTLS przez niezabezpieczony port