
CVE-2024-38826 – CVE-2024-38826 Cloud Controller Denial of Service Attack
https://notcve.org/view.php?id=CVE-2024-38826
11 Nov 2024 — Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller. The Cloud Foundry project recommends upgrading the following releases: * Upgrade capi release version to 1.194.0 or greater * Upgrade cf-deployment version to v44.1.0 or greater. This includes a patched capi release • https://www.cloudfoundry.org/blog/cve-2024-38826-cloud-controller-denial-of-service-attack • CWE-400: Uncontrolled Resource Consumption •

CVE-2024-37082
https://notcve.org/view.php?id=CVE-2024-37082
03 Jul 2024 — Security check loophole in HAProxy release (in combination with routing release) in Cloud Foundry prior to v40.17.0 potentially allows bypass of mTLS authentication to applications hosted on Cloud Foundry. La laguna de control de seguridad en la versión HAProxy (en combinación con la versión de enrutamiento) en Cloud Foundry anterior a v40.17.0 potencialmente permite omitir la autenticación mTLS en aplicaciones alojadas en Cloud Foundry. When deploying Cloud Foundry together with the haproxy-boshrelease and... • https://www.cloudfoundry.org/blog/cve-2024-37082-mtls-bypass • CWE-290: Authentication Bypass by Spoofing •

CVE-2020-5422 – UAA password may appear in BOSH System Metrics Server process arguments
https://notcve.org/view.php?id=CVE-2020-5422
02 Oct 2020 — BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details). BOSH System Metrics Server versiones anteriores a 0.1.0, exponían la contraseña UAA como un flag para un proceso que es ejecutado en el director de BOSH. Expuso la contraseña a cualquier usuario o proceso con acceso a la misma VM (por medio de ps o observando ... • https://www.cloudfoundry.org/blog/cve-2020-5422 • CWE-214: Invocation of Process Using Visible Sensitive Information CWE-668: Exposure of Resource to Wrong Sphere •

CVE-2019-11271 – Bosh Deployment logs leak sensitive information
https://notcve.org/view.php?id=CVE-2019-11271
18 Jun 2019 — Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest. Cloud Foundry BOSH versión 270.x anteriores a v270.1.1, contienen un Director BOSH que no corrige las credenciales cuando se configura para usar una base de datos MySQL. Un usuario malicioso autenticado local puede leer cualquier credencial que esté c... • https://www.cloudfoundry.org/blog/cve-2019-11271 • CWE-522: Insufficiently Protected Credentials CWE-532: Insertion of Sensitive Information into Log File •

CVE-2018-15800 – Timing attack allows extraction of signing key in Bits Service
https://notcve.org/view.php?id=CVE-2018-15800
10 Dec 2018 — Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage. En ParsePayloadHeader de payload_metadata.cc, hay una posible escritura fuera de límites debido a un desbordamiento de enteros. Esto podría llevar a un escalado de privilegios remoto sin necesitar privilegios de ejecución adicionales. No se neces... • https://www.cloudfoundry.org/blog/cve-2018-15800 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2018-15755 – CF networking internal policy server SQL injection
https://notcve.org/view.php?id=CVE-2018-15755
12 Oct 2018 — Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server. Cloud Foundry CF Networking Release, en versiones 2.11.0 anteriores a la 2.16.0, contiene un endpoint de API interno vulnerable a una inyección SWL entre las celdas Diego y el servidor de políticas. Un usuario aute... • https://www.cloudfoundry.org/blog/cve-2018-15755 • CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') •

CVE-2018-11083 – Bosh accepts refresh tokens in place of an access token
https://notcve.org/view.php?id=CVE-2018-11083
05 Oct 2018 — Cloud Foundry BOSH, versions v264 prior to v264.14.0 and v265 prior to v265.7.0 and v266 prior to v266.8.0 and v267 prior to v267.2.0, allows refresh tokens to be as access tokens when using UAA for authentication. A remote attacker with an admin refresh token given by UAA can be used to access BOSH resources without obtaining an access token, even if their user no longer has access to those resources. Cloud Foundry BOSH, en versiones v264 anteriores a la v264.14.0, versiones v265 anteriores a la v265.7.0, ... • https://www.cloudfoundry.org/blog/cve-2018-11083 •

CVE-2017-4961
https://notcve.org/view.php?id=CVE-2017-4961
13 Jun 2017 — An issue was discovered in Cloud Foundry Foundation BOSH Release 261.x versions prior to 261.3 and all 260.x versions. In certain cases an authenticated Director user can provide a malicious checksum that could allow them to escalate their privileges on the Director VM, aka "BOSH Director Shell Injection Vulnerabilities." Se detectó un problema en las versiones de BOSH versión 261.x anteriores a 261.3 y en todas las versiones de 260.x de Cloud Foundry Foundation. En ciertos casos, un usuario Director identi... • https://www.cloudfoundry.org/cve-2017-4961 • CWE-354: Improper Validation of Integrity Check Value •

CVE-2016-3091
https://notcve.org/view.php?id=CVE-2016-3091
08 Jun 2017 — Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service. Cloud Foundry Diego versiones 0.1468.0 hasta 0.1470.0, permite a los atacantes remotos causar una denegación de servicio. • http://www.openwall.com/lists/oss-security/2016/05/17/8 • CWE-19: Data Processing Errors •