PT-2020-18457 · Cloud Foundry · Cloud Foundry Routing Release

Nathan Davison

·

Published

2020-02-27

·

Updated

2020-03-03

·

CVE-2020-5401

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Cloud Foundry Routing Release versions prior to 0.197.0
Description The issue allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app. This is a cache poisoning denial-of-service (DoS) issue.
Recommendations For versions prior to 0.197.0, update to version 0.197.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the caching layers to minimize the risk of exploitation.

Fix

HTTP Request/Response Smuggling

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5401

Affected Products

Cloud Foundry Routing Release