Medium severity4.3NVD Advisory· Published Sep 3, 2020· Updated Jun 17, 2026
CVE-2020-5418
CVE-2020-5418
Description
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
5- Range: <1.98.0
- Cloud Foundry/CAPIv5Range: All
- Cloud Foundry/CF Deploymentv5Range: All
Patches
Vulnerability mechanics
References
1- www.cloudfoundry.org/blog/cve-2020-5418nvdVendor Advisory
News mentions
0No linked articles in our index yet.