Severity
High
Vendor
Cloud Foundry Foundation
Description
Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool.
Affected Cloud Foundry Products and Versions
Severity is high unless otherwise noted.
- Routing
- All versions prior to 0.204.0
- CF Deployment
- All versions prior to 13.13.0
Mitigation
Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:
- Routing
- Upgrade all versions to 0.204.0 or greater
- CF Deployment
- Upgrade all versions to 13.13.0 or greater
History
2020-08-13: Initial vulnerability report published.