CVE-2024-38826
Severity CVSS v4.0:
MEDIUM
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
11/11/2024
Last modified:
17/03/2025
Description
Authenticated users can upload specifically crafted files to leak server resources. This behavior can potentially be used to run a denial of service attack against Cloud Controller.<br />
<br />
The Cloud Foundry project recommends upgrading the following releases:<br />
<br />
* Upgrade capi release version to 1.194.0 or greater<br />
* Upgrade cf-deployment version to v44.1.0 or greater. This includes a patched capi release



