CVE-2018-1221: Input Validation
In cf-deployment before 1.14.0 and routing-release before 0.172.0, the Cloud Foundry Gorouter mishandles WebSocket requests for AWS Application Load Balancers (ALBs) and some other HTTP-aware Load Balancers. A user with developer privileges could use this vulnerability to steal data or cause denial of service.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2018-1221.
What software is affected by this vulnerability?
cf-deployment versions before 1.14.0 and routing-release versions before 0.172.0 are affected.
What is the severity of CVE-2018-1221?
The severity of CVE-2018-1221 is high with a CVSS score of 8.1.
How does this vulnerability impact Cloud Foundry Gorouter?
This vulnerability allows a user with developer privileges to steal data or cause denial of service in Cloud Foundry Gorouter.
How can I fix this vulnerability?
To fix this vulnerability, upgrade to cf-deployment version 1.14.0 or higher and routing-release version 0.172.0 or higher.