CVE-2020-5420: Gorouter is vulnerable to DoS attack via invalid HTTP responses
Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 allow a malicious developer with "cf push" access to cause denial-of-service to the CF cluster by pushing an app that returns specially crafted HTTP responses that crash the Gorouters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-5420?
CVE-2020-5420 is a vulnerability in Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 that allows a malicious developer to cause denial-of-service to the CF cluster.
How can a malicious developer exploit CVE-2020-5420?
A malicious developer with "cf push" access can push an app that returns specially crafted HTTP responses to crash the Gorouters.
What is the severity of CVE-2020-5420?
CVE-2020-5420 has a severity rating of 7.7 (high).
Which software versions are affected by CVE-2020-5420?
Cloud Foundry Routing (Gorouter) versions prior to 0.206.0 and Cloud Foundry CF-deployment versions up to and excluding 13.15.0 are affected by CVE-2020-5420.
Is there a fix available for CVE-2020-5420?
Yes, users should update to Cloud Foundry Routing (Gorouter) version 0.206.0 or newer to fix CVE-2020-5420.