Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:0448C5DFC01FB5FA84DB087FBB7B2C78
HistorySep 01, 2020 - 12:00 a.m.

CVE-2020-5420: Gorouter is vulnerable to DoS attack via invalid HTTP responses | Cloud Foundry

2020-09-0100:00:00
Cloud Foundry
www.cloudfoundry.org
27
cloud foundry
gorouter
dos
cve-2020-5420
http responses
security advisory

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

44.5%

Severity

High

Vendor

Cloud Foundry Foundation

Description

Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with “cf push” access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters.

Affected Cloud Foundry Products and Versions

Severity is high unless otherwise noted.

  • Routing
    • All versions prior to 0.206.0
  • CF Deployment
    • All versions prior to 13.15.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • Routing
    • Upgrade all versions to 0.206.0 or greater
  • CF Deployment
    • Upgrade all versions to 13.15.0 or greater

History

2020-09-01: Initial vulnerability report published.

Affected configurations

Vulners
Node
cloudfoundryrouting-releaseRange<0.206.0
OR
cloudfoundrycf-deploymentRange<13.15.0
VendorProductVersionCPE
cloudfoundryrouting-release*cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:*
cloudfoundrycf-deployment*cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*

CVSS2

6.8

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:N/I:N/A:C

CVSS3

7.7

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

44.5%

Related for CFOUNDRY:0448C5DFC01FB5FA84DB087FBB7B2C78