Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
143 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 1.1% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 23/5/2018 | 17/6/2026 | Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections. | |
| Modificada | Alta (7.2) | 1.3% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releaseCloudfoundry Cf-deployment | 15/5/2018 | 17/6/2026 | Cloud Foundry Foundation UAA, versions 4.12.X and 4.13.X, introduced a feature which could allow privilege escalation across identity zones for clients performing offline validation. A zone administrator could configure their zone to issue tokens which impersonate another zone, granting up to admin privileges in the… | |
| Modificada | Media (5.3) | 0.97% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 18/4/2018 | 17/6/2026 | Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a business logic flaw. An application developer may create an application with a route that conflicts with a platform service route and receive traffic intended for the service. | |
| Modificada | Crítica (9.6) | 0.87% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime | 29/3/2018 | 17/6/2026 | Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the buildpack through the CLI. For example, the user could include a… | |
| Modificada | Alta (8.8) | 0.92% | — | Cloudfoundry Cf-deploymentCloudfoundry Garden-runc-release | 29/3/2018 | 17/6/2026 | Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials. | |
| Modificada | Alta (8.1) | 0.98% | — | Cloudfoundry Silk-release | 27/3/2018 | 17/6/2026 | Cloud Foundry Silk CNI plugin, versions prior to 0.2.0, contains an improper access control vulnerability. If the platform is configured with an application security group (ASG) that overlaps with the Silk overlay network, any applications can reach any other application on the network regardless of the configured… | |
| Modificada | Alta (8.1) | 1.1% | — | Cloudfoundry Capi-release | 27/3/2018 | 17/6/2026 | Cloud Foundry Cloud Controller, versions prior to 1.52.0, contains information disclosure and path traversal vulnerabilities. An authenticated malicious user can predict the location of application blobs and leverage path traversal to create a malicious application that has the ability to overwrite arbitrary files on… | |
| Modificada | Alta (8.1) | 1.2% | — | Cloudfoundry Cf-deploymentCloudfoundry Routing-release | 19/3/2018 | 17/6/2026 | In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service. | |
| Modificada | Alta (8.8) | 0.98% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 19/3/2018 | 17/6/2026 | In Cloud Controller versions prior to 1.46.0, cf-deployment versions prior to 1.3.0, and cf-release versions prior to 283, Cloud Controller accepts refresh tokens for authentication where access tokens are expected. This exposes a vulnerability where a refresh token that would otherwise be insufficient to obtain an… | |
| Modificada | Alta (8.8) | 1.0% | — | Pivotal Software Cloud Foundry UAAPivotal Software Cloud Foundry Uaa-releasePivotal Software Cloud Foundry Cf-releasePivotal Software Cloud Foundry Cf-deployment | 1/2/2018 | 17/6/2026 | In Cloud Foundry Foundation cf-release versions prior to v285; cf-deployment versions prior to v1.7; UAA 4.5.x versions prior to 4.5.5, 4.8.x versions prior to 4.8.3, and 4.7.x versions prior to 4.7.4; and UAA-release 45.7.x versions prior to 45.7, 52.7.x versions prior to 52.7, and 53.3.x versions prior to 53.3, the… | |
| Modificada | Alta (8.8) | 1.0% | — | Jenkins Release | 23/1/2018 | 17/6/2026 | Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigger release builds. | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry Cf-releasePivotal UAAPivotal UAA Bosh | 4/1/2018 | 17/6/2026 | An issue was discovered in these Pivotal Cloud Foundry products: all versions prior to cf-release v270, UAA v3.x prior to v3.20.2, and UAA bosh v30.x versions prior to v30.8 and all other versions prior to v45.0. A cross-site scripting (XSS) attack is possible in the clientId parameter of a request to the UAA OpenID… | |
| Modificada | Media (6.5) | 0.95% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-deploymentCloudfoundry Cf-release | 28/11/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a… | |
| Modificada | Alta (8.8) | 0.95% | — | Pivotal Software Credhub-release | 27/11/2017 | 17/6/2026 | In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint, allowing authenticated applications to view any credential… | |
| Modificada | Media (5.3) | 1.1% | — | Cloudfoundry Cf-releaseCloudfoundry Uaa-release | 27/11/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particular client to revoke client tokens for other users on the same… | |
| Modificada | Alta (8.8) | 1.0% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA | 24/10/2017 | 17/6/2026 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact via vectors involving emails with password recovery links, aka "Cross Domain Referer Leakage." | |
| Modificada | Crítica (9.8) | 1.2% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA | 24/10/2017 | 17/6/2026 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire password reset links. | |
| Modificada | Crítica (9.8) | 1.2% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA | 24/10/2017 | 17/6/2026 | The password change functionality in Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow attackers to have unspecified impact by leveraging failure to expire existing sessions. | |
| Modificada | Alta (8.8) | 0.76% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA | 24/10/2017 | 17/6/2026 | Cloud Foundry Runtime cf-release before 216, UAA before 2.5.2, and Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.7.0 allow remote attackers to conduct cross-site request forgery (CSRF) attacks on PWS and log a user into an arbitrary account by leveraging lack of CSRF checks. | |
| Modificada | Alta (7.8) | 1.2% | — | Cloudfoundry Cf-releasePivotal Capi-release | 4/10/2017 | 17/6/2026 | In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.… | |
| Modificada | Media (6.1) | 0.78% | — | Cloudfoundry Cf-releasePivotal Routing-release | 4/10/2017 | 17/6/2026 | In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user… | |
| Modificada | Alta (8.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime | 7/9/2017 | 17/6/2026 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations… | |
| Modificada | Media (4.7) | 0.54% | — | Cloudfoundry Cf-release | 31/8/2017 | 17/6/2026 | Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests. | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 21/8/2017 | 17/6/2026 | In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035 you should also upgrade to fix this CVE. A carefully crafted CAPI request from a Space… | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 25/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for… |