CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HCloudfoundry Capi Release
APPCloudfoundry< 1.101.0Cloudfoundry Cf Deployment
APPCloudfoundry< 15.0.0
Related vulnerabilities
Cloudfoundry Diego — pominięcie uwierzytelniania mTLS przez niezabezpieczony port
Cloud Foundry cf-deployment: wstrzyknięcie kodu przez niezaszyfrowany protokół pobierania zależności
Cloud foundry instances having CAPI version between 1.140 and 1.152.0 along with loggregator-agent v7+ may ove...
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerabil...
In UAA versions prior to 75.3.0, sensitive information like relaying secret of the provider was revealed in re...