CVE-2020-5423
02.12.2020, 02:15
CAPI (Cloud Controller) versions prior to 1.101.0 are vulnerable to a denial-of-service attack in which an unauthenticated malicious attacker can send specially-crafted YAML files to certain endpoints, causing the YAML parser to consume excessive CPU and RAM.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | capi-release | 𝑥 < 1.101.0 |
cloudfoundry | cf-deployment | 𝑥 < 15.0.0 |
𝑥
= Vulnerable software versions