Severity
Medium
Vendor
Cloud Foundry Foundation
Description
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.88.0, contain a vulnerable version of the Loofah gem for Ruby. Unsanitized JavaScript may occur in sanitized output when a crafted SVG element is republished.
Affected Cloud Foundry Products and Versions
- CF Deployment
- All versions prior to v12.7.0
- CAPI
- All versions prior to 1.88.0
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
- CF Deployment
- Upgrade All versions to v12.7.0 or greater
- CAPI
- Upgrade All versions to 1.88.0 or greater
History
2019-11-12: Initial vulnerability report published.