PT-2022-9228 · Cloud Foundry · Cloud Foundry Capi
Florian Braun
·
Published
2022-03-25
·
Updated
2022-04-04
·
CVE-2021-22100
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Cloud Foundry CAPI versions prior to 1.122
Description
A denial-of-service attack is possible, where a developer can push a service broker that causes CC instances to timeout and fail. This can be done accidentally or maliciously, allowing an attacker to cause an inability for anyone to push or manage apps.
Recommendations
For Cloud Foundry CAPI versions prior to 1.122, update to version 1.122 or later to resolve the issue. As a temporary workaround, consider restricting access to service brokers to minimize the risk of exploitation.
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloud Foundry Capi