Vulnerability Name:

CVE-2016-0713 (CCN-131327)

Assigned:2015-12-16
Published:2016-02-02
Updated:2017-09-05
Summary:Gorouter in Cloud Foundry cf-release v141 through v228 allows man-in-the-middle attackers to conduct cross-site scripting (XSS) attacks via vectors related to modified requests.
CVSS v3 Severity:4.7 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N)
4.5 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): High
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
6.1 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
5.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N/E:H/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Network
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): Required
Scope:Scope (S): Changed
Impact Metrics:Confidentiality (C): Low
Integrity (I): Low
Availibility (A): None
CVSS v2 Severity:2.6 Low (CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): High
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): Partial
Availibility (A): None
5.5 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:S/C:P/I:P/A:N)
Exploitability Metrics:Access Vector (AV): Network
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): Partial
Integrity (I): Partial
Availibility (A): None
Vulnerability Type:CWE-79
Vulnerability Consequences:Cross-Site Scripting
References:Source: MITRE
Type: CNA
CVE-2016-0713

Source: CONFIRM
Type: Release Notes, Third Party Advisory
https://bosh.io/releases/github.com/cloudfoundry/cf-release?version=229

Source: XF
Type: UNKNOWN
cloudfoundry-cve20160713-xss(131327)

Source: CCN
Type: CloudFoundry Web site
CVE-2016-0713 Gorouter XSS

Source: MLIST
Type: Vendor Advisory
[cf-dev] 20160201 CVE-2016-0713 Gorouter XSS

Vulnerable Configuration:Configuration 1:
  • cpe:/a:cloudfoundry:cf-release:141:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:142:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:143:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:144:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:145:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:146:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:147:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:148:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:149:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:150:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:151:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:152:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:153:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:154:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:155:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:156:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:157:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:158:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:159:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:160:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:161:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:162:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:163:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:164:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:165:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:166:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:167:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:168:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:169:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:170:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:171:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:172:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:173:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:174:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:175:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:176:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:177:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:178:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:179:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:180:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:181:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:182:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:183:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:184:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:185:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:186:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:187:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:188:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:189:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:190:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:191:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:192:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:193:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:194:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:195:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:196:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:197:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:198:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:199:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:200:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:201:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:202:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:203:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:204:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:205:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:206:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:207:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:208:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:209:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:210:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:211:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:212:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:213:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:214:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:215:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:216:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:217:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:218:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:219:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:220:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:221:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:222:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:223:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:224:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:225:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:226:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:227:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:228:*:*:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/a:cloud_foundry:cf-release:228:*:*:*:*:*:*:*
  • OR cpe:/a:cloudfoundry:cf-release:141:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    BACK
    cloudfoundry cf-release 141
    cloudfoundry cf-release 142
    cloudfoundry cf-release 143
    cloudfoundry cf-release 144
    cloudfoundry cf-release 145
    cloudfoundry cf-release 146
    cloudfoundry cf-release 147
    cloudfoundry cf-release 148
    cloudfoundry cf-release 149
    cloudfoundry cf-release 150
    cloudfoundry cf-release 151
    cloudfoundry cf-release 152
    cloudfoundry cf-release 153
    cloudfoundry cf-release 154
    cloudfoundry cf-release 155
    cloudfoundry cf-release 156
    cloudfoundry cf-release 157
    cloudfoundry cf-release 158
    cloudfoundry cf-release 159
    cloudfoundry cf-release 160
    cloudfoundry cf-release 161
    cloudfoundry cf-release 162
    cloudfoundry cf-release 163
    cloudfoundry cf-release 164
    cloudfoundry cf-release 165
    cloudfoundry cf-release 166
    cloudfoundry cf-release 167
    cloudfoundry cf-release 168
    cloudfoundry cf-release 169
    cloudfoundry cf-release 170
    cloudfoundry cf-release 171
    cloudfoundry cf-release 172
    cloudfoundry cf-release 173
    cloudfoundry cf-release 174
    cloudfoundry cf-release 175
    cloudfoundry cf-release 176
    cloudfoundry cf-release 177
    cloudfoundry cf-release 178
    cloudfoundry cf-release 179
    cloudfoundry cf-release 180
    cloudfoundry cf-release 181
    cloudfoundry cf-release 182
    cloudfoundry cf-release 183
    cloudfoundry cf-release 184
    cloudfoundry cf-release 185
    cloudfoundry cf-release 186
    cloudfoundry cf-release 187
    cloudfoundry cf-release 188
    cloudfoundry cf-release 189
    cloudfoundry cf-release 190
    cloudfoundry cf-release 191
    cloudfoundry cf-release 192
    cloudfoundry cf-release 193
    cloudfoundry cf-release 194
    cloudfoundry cf-release 195
    cloudfoundry cf-release 196
    cloudfoundry cf-release 197
    cloudfoundry cf-release 198
    cloudfoundry cf-release 199
    cloudfoundry cf-release 200
    cloudfoundry cf-release 201
    cloudfoundry cf-release 202
    cloudfoundry cf-release 203
    cloudfoundry cf-release 204
    cloudfoundry cf-release 205
    cloudfoundry cf-release 206
    cloudfoundry cf-release 207
    cloudfoundry cf-release 208
    cloudfoundry cf-release 209
    cloudfoundry cf-release 210
    cloudfoundry cf-release 211
    cloudfoundry cf-release 212
    cloudfoundry cf-release 213
    cloudfoundry cf-release 214
    cloudfoundry cf-release 215
    cloudfoundry cf-release 216
    cloudfoundry cf-release 217
    cloudfoundry cf-release 218
    cloudfoundry cf-release 219
    cloudfoundry cf-release 220
    cloudfoundry cf-release 221
    cloudfoundry cf-release 222
    cloudfoundry cf-release 223
    cloudfoundry cf-release 224
    cloudfoundry cf-release 225
    cloudfoundry cf-release 226
    cloudfoundry cf-release 227
    cloudfoundry cf-release 228
    cloud_foundry cf-release 228
    cloudfoundry cf-release 141