CVE-2020-5416

Severity CVSS v4.0:
Pending analysis
Type:
CWE-404 Improper Resource Shutdown or Release
Publication date:
21/08/2020
Last modified:
07/06/2021

Description

Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 13.13.0 (excluding)
cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:* 0.204.0 (excluding)


References to Advisories, Solutions, and Tools