CVE-2016-0713Cross-site Scripting in Cf-release

Severity
4.7MEDIUMNVD
EPSS
0.2%
top 52.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedAug 31
Latest updateMay 17

Description

Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.

CVSS vector

CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:NExploitability: 1.6 | Impact: 2.7

Affected Packages1 packages

NVDcloudfoundry/cf-release88 versions+87

🔴Vulnerability Details

2
GHSA
GHSA-84x8-jf5h-4974: Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors re2022-05-17
CVEList
CVE-2016-0713: Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors re2017-08-31
CVE-2016-0713 — Cross-site Scripting in Cf-release | cvebase