Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Cloudfoundry Cf-releasePivotal Capi-release | 4/10/2017 | 17/6/2026 | In Cloud Foundry capi-release versions 1.33.0 and later, prior to 1.42.0 and cf-release versions 268 and later, prior to 274, the original fix for CVE-2017-8033 introduces an API regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially crafted application.… | |
| Modificada | Media (6.1) | 0.78% | — | Cloudfoundry Cf-releasePivotal Routing-release | 4/10/2017 | 17/6/2026 | In Cloud Foundry router routing-release all versions prior to v0.163.0 and cf-release all versions prior to v274, in some applications, it is possible to append a combination of characters to the URL that will allow for an open redirect. An attacker could exploit this as a phishing attack to gain access to user… | |
| Modificada | Alta (8.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry User Account AND AuthenticationCloudfoundry Uaa-releasePivotal Elastic Runtime | 7/9/2017 | 17/6/2026 | The identity zones feature in Pivotal Cloud Foundry 208 through 229; UAA 2.0.0 through 2.7.3 and 3.0.0; UAA-Release 2 through 4, when configured with multiple identity zones; and Elastic Runtime 1.6.0 through 1.6.13 allows remote authenticated users with privileges in one zone to gain privileges and perform operations… | |
| Modificada | Media (4.7) | 0.54% | — | Cloudfoundry Cf-release | 31/8/2017 | 17/6/2026 | Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests. | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 21/8/2017 | 17/6/2026 | In Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.38.0 and cf-release versions after v244 and prior to v270, there is an incomplete fix for CVE-2017-8035. If you took steps to remediate CVE-2017-8035 you should also upgrade to fix this CVE. A carefully crafted CAPI request from a Space… | |
| Modificada | Alta (7.5) | 1.4% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 25/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions after v1.6.0 and prior to v1.35.0 and cf-release versions after v244 and prior to v268. A carefully crafted CAPI request from a Space Developer can allow them to gain access to files on the Cloud Controller VM for… | |
| Modificada | Alta (7.8) | 1.0% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 25/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release versions prior to v1.35.0 and cf-release versions prior to v268. A filesystem traversal vulnerability exists in the Cloud Controller that allows a space developer to escalate privileges by pushing a specially crafted… | |
| Modificada | Alta (7.8) | 1.4% | — | Cloudfoundry Capi-release | 24/7/2017 | 17/6/2026 | An issue was discovered in the Cloud Controller API in Cloud Foundry Foundation CAPI-release version 1.33.0 (only). The original fix for CVE-2017-8033 included in CAPI-release 1.33.0 introduces a regression that allows a space developer to execute arbitrary code on the Cloud Controller VM by pushing a specially… | |
| Modificada | Media (6.6) | 0.75% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-releaseCloudfoundry Routing-release | 17/7/2017 | 17/6/2026 | The Cloud Controller and Router in Cloud Foundry (CAPI-release capi versions prior to v1.32.0, Routing-release versions prior to v0.159.0, CF-release versions prior to v267) do not validate the issuer on JSON Web Tokens (JWTs) from UAA. With certain multi-zone UAA configurations, zone administrators are able to… | |
| Modificada | Media (6.6) | 0.88% | — | Pivotal Software Cloud Foundry UAACloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CF | 10/7/2017 | 17/6/2026 | In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.17, 24.x versions prior to… | |
| Modificada | Alta (7.5) | 1.1% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.16, 24.x versions prior… | |
| Modificada | Crítica (9.8) | 1.2% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v261; UAA release 2.x versions prior to v2.7.4.17, 3.6.x versions prior to v3.6.11, 3.9.x versions prior to v3.9.13, and other versions prior to v4.2.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.15, 24.x versions prior… | |
| Modificada | Alta (7.2) | 0.94% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.14, 24.x versions… | |
| Modificada | Media (6.5) | 0.97% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v258; UAA release 2.x versions prior to v2.7.4.15, 3.6.x versions prior to v3.6.9, 3.9.x versions prior to v3.9.11, and other versions prior to v3.16.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.13, 24.x versions prior… | |
| Modificada | Alta (8.8) | 1.1% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry CFPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior… | |
| Modificada | Alta (7.5) | 1.1% | — | Cloudfoundry Cf-releaseCloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud Foundry UAA | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release (uaa-release) 13.x versions prior to v13.12, 24.x versions prior… | |
| Modificada | Media (5.9) | 0.69% | — | Cloudfoundry Cf-releaseCloudfoundry Staticfile Buildpack | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release v255 and Staticfile buildpack versions v1.4.0 - v1.4.3. A regression introduced in the Static file build pack causes the Staticfile.auth configuration to be ignored when the Static file file is not present in the application root. Applications containing a… | |
| Modificada | Media (6.5) | 0.97% | — | Cloudfoundry Capi-releaseCloudfoundry Cf-release | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation cf-release versions prior to 250 and CAPI-release versions prior to 1.12.0. A user with the SpaceAuditor role is over-privileged with the ability to restage applications. This could cause application downtime if the restage fails. | |
| Modificada | Crítica (9.8) | 1.3% | — | Cloudfoundry Cf-releaseCloudfoundry Routing-release | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to the routing API, aka an "Unauthenticated JWT signing algorithm… | |
| Modificada | Crítica (9.8) | 3.4% | — | Cloudfoundry Cf-mysql-releaseCloudfoundry Cf-release | 13/6/2017 | 17/6/2026 | An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by many Cloud Foundry components. A malicious user may exploit numerous vectors to execute arbitrary… | |
| Modificada | Alta (8.1) | 1.2% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+1 | 25/5/2017 | 17/6/2026 | The UAA reset password flow in Cloud Foundry release v236 and earlier versions, UAA release v3.3.0 and earlier versions, all versions of Login-server, UAA release v10 and earlier versions and Pivotal Elastic Runtime versions prior to 1.7.2 is vulnerable to a brute force attack due to multiple active codes at a given… | |
| Modificada | Media (6.5) | 0.86% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime | 25/5/2017 | 17/6/2026 | The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly… | |
| Modificada | Media (6.1) | 0.66% | — | Cloudfoundry Cloud Foundry UAA BoshPivotal Software Cloud FoundryPivotal Software Cloud Foundry Elastic RuntimePivotal Software Cloud Foundry UAA+1 | 25/5/2017 | 17/6/2026 | The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specifying malicious java script content in either the OAuth scopes… | |
| Modificada | Alta (7.5) | 1.2% | — | Cloudfoundry Cf-releasePivotal Software Cloud Foundry Elastic Runtime | 25/5/2017 | 17/6/2026 | It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attacker could use an improper disk quota value to bypass enforcement… | |
| Modificada | Crítica (9.8) | 1.6% | — | Cloudfoundry Garden LinuxPivotal Software Cloud Foundry Elastic Runtime | 25/5/2017 | 17/6/2026 | Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directories, including other container filesystems on the host. |