Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Advisories
Source ID Title
EUVD EUVD EUVD-2018-11829 Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T03:47:48.896Z

Reserved: 2017-12-06T00:00:00

Link: CVE-2018-1193

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-23T15:29:00.253

Modified: 2024-11-21T03:59:22.253

Link: CVE-2018-1193

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.