cloudfoundry cf-release CVE-2016-2165 in Cloudfoundry and Pivotal Software Products
Published on May 25, 2017

product logo product logo
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.

NVD


Products Associated with CVE-2016-2165

stack.watch emails you whenever new vulnerabilities are published in Cloudfoundry Cf Release or Pivotal Software Cloud Foundry Elastic Runtime. Just hit a watch button to start following.

 
 

Affected Versions

Pivotal Cloud Foundry:

Exploit Probability

EPSS
0.26%
Percentile
48.54%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.