Description
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.
Published: 2017-05-25
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2016-3254 The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.
References
History

No history.

Subscriptions

Cloudfoundry Cf-release
Pivotal Software Cloud Foundry Elastic Runtime
cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-08-05T23:17:50.673Z

Reserved: 2016-01-29T00:00:00.000Z

Link: CVE-2016-2165

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2017-05-25T17:29:00.600

Modified: 2025-04-20T01:37:25.860

Link: CVE-2016-2165

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses