VYPR

CAPI

by Cloudfoundry

CVEs (4)

  • CVE-2020-5417HigAug 21, 2020
    risk 0.57cvss 8.8epss 0.01

    Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the system domain (which is true in the default CF Deployment manifest), were vulnerable to developers maliciously or accidentally claiming certain sensitive…

  • CVE-2020-5423HigDec 2, 2020
    risk 0.49cvss 7.5epss 0.01

    CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.

  • CVE-2021-22100MedMar 25, 2022
    risk 0.35cvss 5.3epss 0.01

    In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for…

  • CVE-2020-5418MedSep 3, 2020
    risk 0.28cvss 4.3epss 0.01

    Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).