Description
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
Published: 2020-02-27
Score: 5.3 Medium
EPSS: 1.0% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2020-26580 Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
History

No history.

Subscriptions

Cloudfoundry Routing Release
cve-icon MITRE

Status: PUBLISHED

Assigner: pivotal

Published:

Updated: 2024-09-16T17:38:11.499Z

Reserved: 2020-01-03T00:00:00.000Z

Link: CVE-2020-5401

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2020-02-27T20:15:11.500

Modified: 2026-06-17T03:21:25.557

Link: CVE-2020-5401

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses
  • CWE-393

    Return of Wrong Status Code

  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')