CAPI
Cloud Foundry- Product type
- Other
- Catalog vulnerabilities
- 6
Severity across 6 analyzed records
Verify to analyze this security profile
en
Severity across 6 analyzed records
Verify to analyze this security profile
As of 09/16/2026, within CyStack's analyzed data, CAPI has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of CAPI and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing | Exploitation statusNot confirmed | FixYes | Published12/02/2020 | SeverityHigh |
CVE-2020-5418Cloud Controller allows users with no roles to list droplets | Exploitation statusNot confirmed | FixYes | Published09/03/2020 | SeverityLow |
CVE-2020-5417Cloud Controller may allow developers to claim sensitive routes | Exploitation statusNot confirmed | FixYes | Published08/21/2020 | SeverityHigh |
CVE-2020-5400Cloud Controller logs environment variables from app manifests | Exploitation statusNot confirmed | FixYes | Published02/27/2020 | SeverityHigh |
CVE-2019-11294CAPI leaks service broker URLs and GUIDs to space developers | Exploitation statusNot confirmed | FixNot confirmed | Published12/19/2019 | SeverityMedium |
CVE-2019-3785Cloud Controller provides signed URL with write authorization to read only user | Exploitation statusNot confirmed | FixYes | Published03/13/2019 | SeverityMedium |