CVE-2020-5420
03.09.2020, 01:15
Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | cf-deployment | 𝑥 < 13.15.0 |
cloudfoundry | gorouter | 𝑥 < 0.206.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration