Логотип exploitDog
bind:CVE-2024-37082
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-37082

Количество 3

Количество 3

nvd логотип

CVE-2024-37082

больше 1 года назад

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.  You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_service”.

CVSS3: 9.1
EPSS: Низкий
github логотип

GHSA-w3h5-p6v5-5vjm

больше 1 года назад

Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows bypass of mTLS authentication to applications hosted on Cloud Foundry.

CVSS3: 9
EPSS: Низкий
fstec логотип

BDU:2024-09482

больше 1 года назад

Уязвимость компонента haproxy-boshrelease платформы для многооблачных приложений Cloud Foundry, позволяющая нарушителю обойти проверку подлинности mTLS

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-37082

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.  You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_service”.

CVSS3: 9.1
0%
Низкий
больше 1 года назад
github логотип
GHSA-w3h5-p6v5-5vjm

Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows bypass of mTLS authentication to applications hosted on Cloud Foundry.

CVSS3: 9
0%
Низкий
больше 1 года назад
fstec логотип
BDU:2024-09482

Уязвимость компонента haproxy-boshrelease платформы для многооблачных приложений Cloud Foundry, позволяющая нарушителю обойти проверку подлинности mTLS

CVSS3: 9.1
0%
Низкий
больше 1 года назад

Уязвимостей на страницу