CVE-2023-34061

EUVD-2023-38175
Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack.  An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.



ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
pivotalcloud_foundry_deployment
0.28.0 ≤
𝑥
≤ 33.5.0
pivotalcloud_foundry_routing_release
0.163.0 ≤
𝑥
≤ 0.283.0
𝑥
= Vulnerable software versions