Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jq2q-gqc9-53g3

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the developer's app handling some requests that were expected to go to certain system components.

Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the developer's app handling some requests that were expected to go to certain system components.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.8
nvd
больше 5 лет назад

Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive routes, potentially resulting in the developer's app handling some requests that were expected to go to certain system components.

EPSS

Процентиль: 56%
0.00336
Низкий

Дефекты

CWE-732