Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

143 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)1.0%—Cloudfoundry Routing Release27/2/202017/6/2026
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
ModificadaMedia (6.5)0.75%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment27/2/202017/6/2026
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.
ModificadaMedia (4.3)0.69%—Jenkins BMC Release Package AND Deployment12/2/202017/6/2026
Jenkins BMC Release Package and Deployment Plugin 1.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
ModificadaMedia (4.3)0.78%—Cloudfoundry Capi-releaseCloudfoundry Cf-deployment19/12/201917/6/2026
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
ModificadaAlta (8.6)1.5%—Cloudfoundry Cf-deploymentCloudfoundry Routing-release19/11/201917/6/2026
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
ModificadaAlta (8.8)1.3%—Cloudfoundry UAA Release26/9/201917/6/2026
CF UAA versions prior to 74.1.0 can request scopes for a client that shouldn't be allowed by submitting an array of requested scopes. A remote malicious user can escalate their own privileges to any scope, allowing them to take control of UAA and the resources it controls.
ModificadaAlta (8.1)1.7%—Cloudfoundry Cf-deploymentCloudfoundry NFS Volume Release23/9/201917/6/2026
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a…
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaMedia (5.5)0.47%—Jenkins M2release31/7/201917/6/2026
Jenkins Maven Release Plugin 0.14.0 and earlier stored credentials unencrypted on the Jenkins master where they could be viewed by users with access to the master file system.
ModificadaMedia (5.4)0.69%—Jenkins M2 Release31/7/201917/6/2026
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
ModificadaMedia (6.3)0.61%—Jenkins M2release31/7/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier in the M2ReleaseAction#doSubmit method allowed attackers to perform releases with attacker-specified options.
ModificadaMedia (4.3)1.0%—Pivotal Software Cloud Foundry Uaa-release11/7/201917/6/2026
Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other…
ModificadaAlta (8.8)1.1%—Pivotal Software Cloud Foundry Uaa-release19/6/201917/6/2026
Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially…
ModificadaCrítica (9.8)0.59%—Cloudfoundry Cf-deploymentCloudfoundry CredhubCloudfoundry UAA Release25/4/201917/6/2026
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
ModificadaMedia (6.1)0.83%—Cloudfoundry UAA Release25/4/201917/6/2026
Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim.
ModificadaMedia (6.5)0.76%—Cloudfoundry Routing Release24/4/201917/6/2026
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a private domain that shadows the external domain of the route service, and map that route to an app. When…
ModificadaAlta (7.5)1.3%—Cloudfoundry Capi-release17/4/201917/6/2026
Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the…
ModificadaAlta (8.1)1.3%—Cloudfoundry Capi-release13/3/201917/6/2026
Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service.
ModificadaMedia (6.5)0.88%—Cloudfoundry UAA Release7/3/201917/6/2026
Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user.
ModificadaAlta (8.8)1.8%—Pivotal Software Cloud Foundry Uaa-release13/12/201817/6/2026
Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of…
ModificadaAlta (8.8)1.7%—Pivotal Software Cloud Foundry UAAPivotal Software Cloudfoundry UAA Release19/11/201817/6/2026
Cloud Foundry UAA release, versions prior to v64.0, and UAA, versions prior to 4.23.0, contains a validation error which allows for privilege escalation. A remote authenticated user may modify the url and content of a consent page to gain a token with arbitrary scopes that escalates their privileges.
ModificadaCrítica (9.8)1.1%—Pivotal Software Cloudfoundry UAAPivotal Software Cloudfoundry UAA Release5/10/201817/6/2026
Cloud Foundry UAA, all versions prior to 4.20.0 and Cloud Foundry UAA Release, all versions prior to 61.0, allows brute forcing of MFA codes. A remote unauthenticated malicious user in possession of a valid username and password can brute force MFA to login as the targeted user.
ModificadaCrítica (9.8)17%—Broadcom Release Automation30/8/201817/6/2026
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.
ModificadaMedia (5.9)1.6%—Cloudfoundry Cf-releaseCloudfoundry Java Buildpack11/7/201817/6/2026
Applications deployed to Cloud Foundry, versions v166 through v227, may be vulnerable to a remote disclosure of information, including, but not limited to environment variables and bound service details. For applications to be vulnerable, they must have been staged using automatic buildpack detection, passed through…
ModificadaMedia (6.1)0.85%—Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-release25/6/201817/6/2026
Cloud Foundry UAA, versions later than 4.6.0 and prior to 4.19.0 except 4.10.1 and 4.7.5 and uaa-release versions later than v48 and prior to v60 except v55.1 and v52.9, does not validate redirect URL values on a form parameter used for internal UAA redirects on the login page, allowing open redirects. A remote…