Vulnerability Name: | CVE-2020-5401 (CCN-177013) | ||||||||||||
Assigned: | 2020-02-24 | ||||||||||||
Published: | 2020-02-24 | ||||||||||||
Updated: | 2020-03-03 | ||||||||||||
Summary: | Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L) 4.6 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L/E:U/RL:O/RC:C)
4.6 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P)
| ||||||||||||
Vulnerability Type: | CWE-444 | ||||||||||||
Vulnerability Consequences: | Gain Access | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2020-5401 Source: XF Type: UNKNOWN cloudfoundry-cve20205401-cache-poisoning(177013) Source: CONFIRM Type: Vendor Advisory https://www.cloudfoundry.org/blog/cve-2020-5401 Source: CCN Type: Cloud Foundry Blog, February 24, 2020 CVE-2020-5401: Cloud Foundry GoRouter is vulnerable to cache poisoning | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||
BACK |