Browse all 73 CVE security advisories affecting Cloud Foundry. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Cloud Foundry is an open-source platform-as-a-service (PaaS) that enables developers to deploy, run, and scale applications across hybrid and multi-cloud environments. Its architecture, which relies on complex component interactions, has historically exposed it to diverse vulnerability classes, including remote code execution, cross-site scripting, and privilege escalation. With seventy-one recorded CVEs, these flaws often stem from input validation errors or misconfigurations within its core components like the Diego scheduler and UAA authentication service. Security incidents have frequently involved unauthorized access to containerized workloads or exploitation of API endpoints, highlighting risks associated with its distributed nature. While the project maintains active security patches, the sheer volume of historical vulnerabilities underscores the complexity of securing its extensive ecosystem. Organizations must rigorously audit configurations and apply updates promptly to mitigate these persistent threats inherent in its open-source, community-driven development model.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2020-5423 | Cloud Controller is vulnerable to denial of service via YAML parsing — CAPI CWE-400 | 7.5 | - | 2020-12-02 |
| CVE-2020-5418 | Cloud Controller allows users with no roles to list droplets — CAPI CWE-863 | 4.3 | - | 2020-09-03 |
| CVE-2020-5417 | Cloud Controller may allow developers to claim sensitive routes — CAPI CWE-732 | 8.1 | - | 2020-08-21 |
| CVE-2020-5400 | Cloud Controller logs environment variables from app manifests — CAPI CWE-522 | 6.5 | - | 2020-02-27 |
| CVE-2019-11294 | CAPI leaks service broker URLs and GUIDs to space developers — CAPI CWE-200 | 4.3 | - | 2019-12-19 |
| CVE-2019-3785 | Cloud Controller provides signed URL with write authorization to read only user — CAPI CWE-285 | 8.1 | - | 2019-03-13 |
This page lists every published CVE security advisory associated with Cloud Foundry. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.