Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
References
Link | Resource |
---|---|
https://www.cloudfoundry.org/blog/cve-2020-5401 | Vendor Advisory |
Configurations
History
No history.
Information
Published : 2020-02-27 20:15
Updated : 2020-03-03 19:43
NVD link : CVE-2020-5401
Mitre link : CVE-2020-5401
JSON object : View
Products Affected
cloudfoundry
- routing_release
CWE
CWE-444
Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')