Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
255 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry User Account AND Authentication | 26/9/2019 | 17/6/2026 | CF UAA versions prior to 74.1.0, allow external input to be directly queried against. A remote malicious user with 'client.write' and 'groups.update' can craft a SCIM query, which leaks information that allows an escalation of privileges, ultimately allowing the malicious user to gain control of UAA scopes they should… | |
| Modificada | Alta (8.1) | 1.7% | — | Cloudfoundry Cf-deploymentCloudfoundry NFS Volume Release | 23/9/2019 | 17/6/2026 | Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a… | |
| Modificada | Media (6.1) | 0.80% | — | Cloudfoundry User Account AND Authentication | 9/8/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to 74.0.0, is vulnerable to an XSS attack. A remote unauthenticated malicious attacker could craft a URL that contains a SCIM filter that contains malicious JavaScript, which older browsers may execute. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.5) | 1.1% | — | Pivotal Software Application ServicePivotal Software Cloud Foundry UAAPivotal Software Operations Manager | 5/8/2019 | 17/6/2026 | Cloud Foundry UAA versions prior to v73.4.0 contain a vulnerability where a malicious client possessing the 'clients.write' authority or scope can bypass the restrictions imposed on clients created via 'clients.write' and create clients with arbitrary scopes that the creator does not possess. | |
| Modificada | Media (5.4) | 1.1% | — | Pivotal Software Cloud Foundry UAA | 18/7/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to v73.4.0, does not set an X-FRAME-OPTIONS header on various endpoints. A remote user can perform clickjacking attacks on UAA's frontend sites. | |
| Modificada | Media (4.3) | 1.0% | — | Pivotal Software Cloud Foundry Uaa-release | 11/7/2019 | 17/6/2026 | Cloud Foundry UAA version prior to 73.3.0, contain endpoints that contains improper escaping. An authenticated malicious user with basic read privileges for one identity zone can extend those reading privileges to all other identity zones and obtain private information on users, clients, and groups in all other… | |
| Modificada | Alta (8.8) | 1.1% | — | Pivotal Software Cloud Foundry Uaa-release | 19/6/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to 73.0.0, falls back to appending “unknown.org” to a user's email address when one is not provided and the user name does not contain an @ character. This domain is held by a private company, which leads to attack vectors including password recovery emails sent to a potentially… | |
| Modificada | Alta (7.8) | 0.29% | — | Cloud Foundry Bosh | 19/6/2019 | 17/6/2026 | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest. | |
| Modificada | Crítica (9.8) | 0.59% | — | Cloudfoundry Cf-deploymentCloudfoundry CredhubCloudfoundry UAA Release | 25/4/2019 | 17/6/2026 | Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component. | |
| Modificada | Media (6.1) | 0.83% | — | Cloudfoundry UAA Release | 25/4/2019 | 17/6/2026 | Cloud Foundry UAA Release, versions prior to 71.0, allows clients to be configured with an insecure redirect uri. Given a UAA client was configured with a wildcard in the redirect uri's subdomain, a remote malicious unauthenticated user can craft a phishing link to get a UAA access code from the victim. | |
| Modificada | Media (6.5) | 0.76% | — | Cloudfoundry Routing Release | 24/4/2019 | 17/6/2026 | Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a private domain that shadows the external domain of the route service, and map that route to an app. When… | |
| Modificada | Alta (7.1) | 0.58% | — | Cloudfoundry Bosh Backup AND Restore | 24/4/2019 | 17/6/2026 | Cloud Foundry BOSH Backup and Restore CLI, all versions prior to 1.5.0, does not check the authenticity of backup scripts in BOSH. A remote authenticated malicious user can modify the metadata file of a Bosh Backup and Restore job to request extra backup files from different jobs upon restore. The exploited hooks in… | |
| Modificada | Alta (7.5) | 1.3% | — | Cloudfoundry Capi-release | 17/4/2019 | 17/6/2026 | Cloud Foundry Cloud Controller API Release, versions prior to 1.79.0, contains improper authentication when validating user permissions. A remote authenticated malicious user with the ability to create UAA clients and knowledge of the email of a victim in the foundation may escalate their privileges to that of the… | |
| Modificada | Alta (8.1) | 1.3% | — | Cloudfoundry Capi-release | 13/3/2019 | 17/6/2026 | Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authenticated malicious user with read permissions can request package information and receive a signed bit-service url that grants the user write permissions to the bit-service. | |
| Modificada | Alta (8.8) | 1.4% | — | Cloudfoundry Container Runtime | 8/3/2019 | 17/6/2026 | Cloud Foundry Container Runtime, versions prior to 0.28.0, deploys K8s worker nodes that contains a configuration file with IAAS credentials. A malicious user with access to the k8s nodes can obtain IAAS credentials allowing the user to escalate privileges to gain access to the IAAS account. | |
| Modificada | Alta (8.8) | 0.67% | — | Cloudfoundry Container Runtime | 8/3/2019 | 17/6/2026 | Cloud Foundry Container Runtime, versions prior to 0.29.0, deploys Kubernetes clusters utilize the same CA (Certificate Authority) to sign and trust certs for ETCD as used by the Kubernetes API. This could allow a user authenticated with a cluster to request a signed certificate leveraging the Kubernetes CSR… | |
| Modificada | Media (6.5) | 1.1% | — | Cloudfoundry Stratos | 7/3/2019 | 17/6/2026 | Cloud Foundry Stratos, versions prior to 2.3.0, contains an insecure session that can be spoofed. When deployed on cloud foundry with multiple instances using the default embedded SQLite database, a remote authenticated malicious user can switch sessions to another user with the same session id. | |
| Modificada | Alta (8.8) | 0.90% | — | Cloudfoundry Stratos | 7/3/2019 | 17/6/2026 | Cloud Foundry Stratos, versions prior to 2.3.0, deploys with a public default session store secret. A malicious user with default session store secret can brute force another user's current Stratos session, and act on behalf of that user. | |
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry Command Line Interface | 7/3/2019 | 17/6/2026 | Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password. | |
| Modificada | Media (6.5) | 0.88% | — | Cloudfoundry UAA Release | 7/3/2019 | 17/6/2026 | Cloud Foundry UAA, versions prior to v70.0, allows a user to update their own email address. A remote authenticated user can impersonate a different user by changing their email address to that of a different user. | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Cloud Foundry | 20/2/2019 | 17/6/2026 | A exposure of sensitive information vulnerability exists in Jenkins Cloud Foundry Plugin 2.3.1 and earlier in AbstractCloudFoundryPushDescriptor.java that allows attackers with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method,… | |
| Modificada | Alta (7.8) | 0.36% | — | Cloudfoundry Credhub CLI | 13/2/2019 | 17/6/2026 | Cloud Foundry CredHub CLI, versions prior to 2.2.1, inadvertently writes authentication credentials provided via environment variables to its persistent config file. A local authenticated malicious user with access to the CredHub CLI config file can use these credentials to retrieve and modify credentials stored in… | |
| Modificada | Alta (8.8) | 1.8% | — | Pivotal Software Cloud Foundry Uaa-release | 13/12/2018 | 17/6/2026 | Cloud Foundry UAA, versions 60 prior to 66.0, contain an authorization logic error. In environments with multiple identity providers that contain accounts across identity providers with the same username, a remote authenticated user with access to one of these accounts may be able to obtain a token for an account of… | |
| Modificada | Media (6.8) | 0.93% | — | Cloud Foundry Bits Service | 10/12/2018 | 17/6/2026 | Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage. |