MEDIUM🇬🇧 English

CVE-2023-20882

CVSS 5.9v3.1pub. 2023-05-26upd. 2025-01-16

In Cloud foundry routing release versions from 0.262.0 and prior to 0.266.0,a bug in the gorouter process can lead to a denial of service of applications hosted on Cloud Foundry. Under the right circumstances, when client connections are closed prematurely, gorouter marks the currently selected backend as failed and removes it from the routing pool.

oryginał EN
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Cloudfoundry Cf Deployment

    APP
    Cloudfoundry
    27.4.0 – 29.0.0 (bez)
  • Cloudfoundry Routing Release

    APP
    Cloudfoundry
    0.262.0 – 0.266.0 (bez)
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
DoS
CWE
Referencje

Powiązane podatności

CVE-2022-31733CRITICAL9.1PL ✓ten sam produkt

Cloudfoundry Diego — pominięcie uwierzytelniania mTLS przez niezabezpieczony port

CVE-2019-3801CRITICAL9.8PL ✓ten sam produkt

Cloud Foundry cf-deployment: wstrzyknięcie kodu przez niezaszyfrowany protokół pobierania zależności

CVE-2023-20881HIGH8.1ten sam produkt

Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may ove...

CVE-2021-22101HIGH7.5ten sam produkt

Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerabil...

CVE-2021-22001HIGH7.5ten sam produkt

In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in re...