惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Y
Y Combinator Blog
Jina AI
Jina AI
雷峰网
雷峰网
有赞技术团队
有赞技术团队
WordPress大学
WordPress大学
美团技术团队
V
V2EX
酷 壳 – CoolShell
酷 壳 – CoolShell
小众软件
小众软件
博客园 - Franky
博客园 - 三生石上(FineUI控件)
月光博客
月光博客
博客园 - 叶小钗
大猫的无限游戏
大猫的无限游戏
爱范儿
爱范儿
Hugging Face - Blog
Hugging Face - Blog
宝玉的分享
宝玉的分享
Last Week in AI
Last Week in AI
Apple Machine Learning Research
Apple Machine Learning Research
量子位
IT之家
IT之家
人人都是产品经理
人人都是产品经理
博客园_首页
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com

Cloud Foundry

USN-4436-1: librsvg vulnerabilities USN-4428-1: Python vulnerabilities USN-4436-2: librsvg regression USN-4431-1: FFmpeg vulnerabilities CVE-2019-3801: Java Projects using HTTP to fetch dependencies
CVE-2019-15225/15226: Envoy 1.11.1 vulnerability fixes
Cloud Foundry Foundation Security Team · 2019-11-12 · via Cloud Foundry

Severity

High

Vendor

Cloud Foundry Foundation

Description

Cloud Foundry Diego, versions prior to 2.39.0, consumes a vulnerable version of Envoy which is vulnerable to a denial-of-service attack. A remote unauthenticated malicious user may craft requests with a large number of headers to consume excess CPU or may send a request with a very long URI to consume excess memory. CF Deployment, versions prior to 12.2.0, is affected through its consumption of Diego.

Affected Cloud Foundry Products and Versions

  • Diego
    • All versions prior to v2.39.0
  • CF Deployment
    • All versions prior to v12.2.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • Diego
    • Upgrade All versions to v2.39.0 or greater
  • CF Deployment
    • Upgrade All versions to v12.2.0 or greater

References

History

2019-11-11: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Sign up for the
Cloud Foundry Newsletter today!