« Volver al listado

CVE-2020-5423

Estado: ModificadaAlta (7.5)—

CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2020-5423",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 7.8,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:C",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 6.9,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ],
    "cvssMetricV30": [
      {
        "type": "Secondary",
        "source": "security@pivotal.io",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.0",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@pivotal.io",
      "affectedData": [
        {
          "vendor": "Cloud Foundry",
          "product": "CAPI",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "1.101.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Cloud Foundry",
          "product": "CF Deployment",
          "versions": [
            {
              "status": "affected",
              "version": "All",
              "lessThan": "15.0.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2020-12-02T02:15:12.033",
  "references": [
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2020-5423",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@pivotal.io"
    },
    {
      "url": "https://www.cloudfoundry.org/blog/cve-2020-5423",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@pivotal.io",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-400"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM."
    },
    {
      "lang": "es",
      "value": "CAPI (Cloud Controller) versiones anteriores a 1.101.0, son vulnerables a un ataque de denegación de servicio en el que un atacante malicioso no autenticado puede enviar archivos YAML especialmente diseñados a determinados endpoints, causando a un analizador YAML consumir una cantidad excesiva de CPU y RAM"
    }
  ],
  "lastModified": "2026-06-17T03:21:28.200",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "02C6575F-86FB-495E-BF4C-B0B25166C96F",
              "versionEndExcluding": "1.101.0"
            },
            {
              "criteria": "cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "027394F1-374F-40DE-858F-04255C165E0D",
              "versionEndExcluding": "15.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@pivotal.io"
}