Filtered by vendor Cloudfoundry Subscriptions
Filtered by product Cf-deployment Subscriptions
Total 42 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2018-1193 1 Cloudfoundry 2 Cf-deployment, Routing-release 2024-11-21 N/A
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
CVE-2018-1191 1 Cloudfoundry 2 Cf-deployment, Garden-runc-release 2024-11-21 N/A
Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.