PT-2024-12464 · Unknown · Cloud Foundry

David Sabeti

+1

·

Published

2024-01-12

·

Updated

2024-01-18

·

CVE-2023-34061

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry routing release versions from v0.163.0 to v0.283.0
Description The issue allows an unauthenticated attacker to force route pruning, which can degrade the service availability of the Cloud Foundry deployment. This is achieved through a DOS attack.
Recommendations For Cloud Foundry routing release versions from v0.163.0 to v0.283.0, consider restricting access to the routing component to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CVE-2023-34061

Affected Products

Cloud Foundry