Vulnerabilidad en Gorouter en Cloud Foundry (CVE-2016-0713)
Gravedad CVSS v3.1:
MEDIA
Tipo:
CWE-79
Neutralización incorrecta de la entrada durante la generación de la página web (Cross-site Scripting)
Fecha de publicación:
31/08/2017
Última modificación:
20/04/2025
Descripción
Gorouter en Cloud Foundry cf-release v141 a v228 permite que los atacantes Man-in-the-Middle (MitM) realicen ataques Cross-Site Scripting (XSS) mediante vectores relacionados con peticiones modificadas.
Impacto
Puntuación base 3.x
4.70
Gravedad 3.x
MEDIA
Puntuación base 2.0
2.60
Gravedad 2.0
BAJA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:cloudfoundry:cf-release:141:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:142:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:143:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:144:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:145:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:146:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:147:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:148:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:149:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:150:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:151:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:152:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:153:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:154:*:*:*:*:*:*:* | ||
| cpe:2.3:a:cloudfoundry:cf-release:155:*:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- https://bosh.io/releases/github.com/cloudfoundry/cf-release?version=229
- https://lists.cloudfoundry.org/archives/list/cf-dev%40lists.cloudfoundry.org/thread/VWDLUNTDKW5CW5JWEM5BOHLJ3J32TAFF/
- https://bosh.io/releases/github.com/cloudfoundry/cf-release?version=229
- https://lists.cloudfoundry.org/archives/list/cf-dev%40lists.cloudfoundry.org/thread/VWDLUNTDKW5CW5JWEM5BOHLJ3J32TAFF/



