Cloudfoundry Capi-Release vulnerabilities
22 known vulnerabilities affecting cloudfoundry/capi-release.
Total CVEs
22
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH13MEDIUM9
Vulnerabilities
Page 2 of 2
CVE-2019-11294P4MEDIUMCVSS 4.3v1.88.02019-12-19
CVE-2019-11294 [MEDIUM] CWE-200 CVE-2019-11294: Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all globa
Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.
nvd
CVE-2020-5418P4MEDIUMCVSS 4.3fixed in 1.98.02020-09-03
CVE-2020-5418 [MEDIUM] CWE-863 CVE-2020-5418: Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only
Cloud Foundry CAPI (Cloud Controller) versions prior to 1.98.0 allow authenticated users having only the "cloud_controller.read" scope, but no roles in any spaces, to list all droplets in all spaces (whereas they should see none).
nvd
← Previous2 / 2