First published: Mon May 21 2018(Updated: )
Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Cf-deployment | <1.27.0 | |
Cloudfoundry Routing-release | <0.175.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2018-1193.
The title of the vulnerability is 'Cloud Foundry routing-release versions prior to 0.175.0 lacks sanitization for user-provided X-Forwarded-Proto headers'.
The vulnerability affects Cloud Foundry routing-release versions prior to 0.175.0.
The severity of CVE-2018-1193 is medium (5.3).
To fix this vulnerability, update your Cloud Foundry routing-release to version 0.175.0 or later.