CVE-2018-1193

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
23/05/2018
Last modified:
03/10/2019

Description

Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 1.27.0 (excluding)
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:* 0.175.0 (excluding)


References to Advisories, Solutions, and Tools