CVE-2018-1221

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
19/03/2018
Last modified:
27/05/2021

Description

In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 1.14.0 (excluding)
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:* 0.172.0 (excluding)


References to Advisories, Solutions, and Tools