PT-2020-18469 · Cloud Foundry · Cloud Foundry Capi

Published

2020-08-21

·

Updated

2021-08-17

·

CVE-2020-5417

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry CAPI (Cloud Controller) versions prior to 1.97.0
Description The issue allows developers to maliciously or accidentally claim certain sensitive routes, potentially resulting in the developer's app handling some requests that were expected to go to certain system components. This occurs when the Cloud Foundry CAPI is used in a deployment where an app domain is also the system domain, which is true in the default CF Deployment manifest.
Recommendations For versions prior to 1.97.0, update to version 1.97.0 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive routes to prevent malicious or accidental claims by developers.

Fix

Incorrect Permission

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5417

Affected Products

Cloud Foundry Capi