RSS   Vulnerabilities for 'Routing-release'   RSS

2017-07-17
 
CVE-2017-8034

CWE-565
 

 
The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to escalate their privileges.

 
2017-06-13
 
CVE-2016-8218

 

 
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm in routing" issue.

 

 >>> Vendor: Cloud foundry 11 Products
Php buildpack
Cf-release
Capi-release
Diego
BOSH
Cf-mysql-release
Routing-release
Staticfile buildpack
Cf-networking
Bits service
Loggregator


Copyright 2024, cxsecurity.com

 

Back to Top