PT-2020-18457 · Cloud Foundry · Cloud Foundry Routing Release
Nathan Davison
·
Published
2020-02-27
·
Updated
2020-03-03
·
CVE-2020-5401
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry Routing Release versions prior to 0.197.0
Description
The issue allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app. This is a cache poisoning denial-of-service (DoS) issue.
Recommendations
For versions prior to 0.197.0, update to version 0.197.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the caching layers to minimize the risk of exploitation.
Fix
HTTP Request/Response Smuggling
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Cloud Foundry Routing Release