惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

大猫的无限游戏
大猫的无限游戏
aimingoo的专栏
aimingoo的专栏
I
InfoQ
B
Blog RSS Feed
D
DataBreaches.Net
S
SegmentFault 最新的问题
P
Proofpoint News Feed
A
About on SuperTechFans
WordPress大学
WordPress大学
Hugging Face - Blog
Hugging Face - Blog
博客园 - 司徒正美
小众软件
小众软件
博客园 - Franky
有赞技术团队
有赞技术团队
D
Docker
T
Tailwind CSS Blog
雷峰网
雷峰网
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Blog — PlanetScale
Blog — PlanetScale
酷 壳 – CoolShell
酷 壳 – CoolShell
B
Blog
V
Visual Studio Blog
宝玉的分享
宝玉的分享
爱范儿
爱范儿

Cloud Foundry

USN-4436-1: librsvg vulnerabilities USN-4428-1: Python vulnerabilities USN-4436-2: librsvg regression USN-4431-1: FFmpeg vulnerabilities CVE-2019-3801: Java Projects using HTTP to fetch dependencies
CVE-2019-15225/15226: Envoy 1.11.1 vulnerability fixes
Cloud Foundry Foundation Security Team · 2019-11-12 · via Cloud Foundry

Severity

High

Vendor

Cloud Foundry Foundation

Description

Cloud Foundry Diego, versions prior to 2.39.0, consumes a vulnerable version of Envoy which is vulnerable to a denial-of-service attack. A remote unauthenticated malicious user may craft requests with a large number of headers to consume excess CPU or may send a request with a very long URI to consume excess memory. CF Deployment, versions prior to 12.2.0, is affected through its consumption of Diego.

Affected Cloud Foundry Products and Versions

  • Diego
    • All versions prior to v2.39.0
  • CF Deployment
    • All versions prior to v12.2.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • Diego
    • Upgrade All versions to v2.39.0 or greater
  • CF Deployment
    • Upgrade All versions to v12.2.0 or greater

References

History

2019-11-11: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Sign up for the
Cloud Foundry Newsletter today!