CF Deployment
Cloud Foundry- Product type
- Other
- Catalog vulnerabilities
- 12
Severity across 12 analyzed records
Verify to analyze this security profile
en
Severity across 12 analyzed records
Verify to analyze this security profile
As of 09/15/2026, within CyStack's analyzed data, CF Deployment has 0 security vulnerabilities published in the last 90 days. Of these, 0 are rated High or Critical. None of these vulnerabilities is listed in the CISA KEV catalog. CyStack recommends that organizations and individual users remediate applicable vulnerabilities as soon as possible.
CyStack does not yet have sufficient official-source data to identify the latest version of CF Deployment and determine which vulnerabilities affect that version.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan| Vulnerability | Exploitation status | Fix | Published | Severity |
|---|---|---|---|---|
CVE-2026-41005UAA accepts SAML Encrypted Assertions authentication bypass | Exploitation statusNot known exploited | FixYes | Published06/11/2026 | SeverityCritical |
CVE-2025-22246CVE-2025-22246 – UAA Private Key Exposure | Exploitation statusNot known exploited | FixYes | Published05/13/2025 | SeverityLow |
CVE-2023-34061CVE-2023-34061 – Gorouter route pruning | Exploitation statusNot known exploited | FixYes | Published01/12/2024 | SeverityHigh |
CVE-2023-34041CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter | Exploitation statusNot confirmed | FixYes | Published09/08/2023 | SeverityMedium |
CVE-2020-5423Cloud Controller is vulnerable to denial of service via YAML parsing | Exploitation statusNot confirmed | FixYes | Published12/02/2020 | SeverityHigh |
CVE-2020-5420Gorouter is vulnerable to DoS attack via invalid HTTP responses | Exploitation statusNot confirmed | FixYes | Published09/03/2020 | SeverityHigh |
CVE-2020-5418Cloud Controller allows users with no roles to list droplets | Exploitation statusNot confirmed | FixYes | Published09/03/2020 | SeverityLow |
CVE-2020-5417Cloud Controller may allow developers to claim sensitive routes | Exploitation statusNot confirmed | FixYes | Published08/21/2020 | SeverityHigh |
CVE-2020-5416CF clusters with NGINX in front of them may be vulnerable to DoS | Exploitation statusNot confirmed | FixYes | Published08/21/2020 | SeverityHigh |
CVE-2019-11283Password leak in smbdriver logs | Exploitation statusNot confirmed | FixYes | Published10/23/2019 | SeverityHigh |
CVE-2019-11282UAA is vulnerable to a Blind SCIM injection leading to information disclosure | Exploitation statusNot confirmed | FixYes | Published10/23/2019 | SeverityMedium |
CVE-2019-11277Volume Services is vulnerable to an LDAP injection attack | Exploitation statusNot confirmed | FixYes | Published09/23/2019 | SeverityHigh |