Known Vulnerabilities for Cloud Controller by Cloudfoundry
Listed below are 5 of the newest known vulnerabilities associated with "Cloud Controller" by "Cloudfoundry".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
More device details and information can be found at device.report here: Cloudfoundry Cloud Controller
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-40868 json | Kyverno is a policy engine designed for cloud native platform engineering teams. Prior to 1.16.4, kyverno’s apiCall service... | Not Provided | 2026-04-21 | 2026-04-22 |
| CVE-2026-33658 json | Active Storage allows users to attach cloud and local files in Rails applications. Prior to versions 8.1.2.1, 8.0.4.1, and 7.... | Not Provided | 2026-03-26 | 2026-03-30 |
| CVE-2026-5412 json | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user ca... | Not Provided | 2026-04-10 | 2026-04-10 |
| CVE-2025-9292 json | A permissive web security configuration may allow cross-origin restrictions enforced by modern browsers to be bypassed under ... | Not Provided | 2026-02-13 | 2026-02-13 |
| CVE-2020-5417 json | Cloud Foundry CAPI (Cloud Controller), versions prior to 1.97.0, when used in a deployment where an app domain is also the sy... | 8.8 - HIGH | 2020-08-21 | 2021-08-17 |
| CVE-2020-5400 json | Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which ... | 6.5 - MEDIUM | 2020-02-27 | 2021-08-17 |
| CVE-2019-11294 json | Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, includ... | 4.3 - MEDIUM | 2019-12-19 | 2021-08-17 |
| CVE-2019-3785 json | Cloud Foundry Cloud Controller, versions prior to 1.78.0, contain an endpoint with improper authorization. A remote authentic... | 8.1 - HIGH | 2019-03-13 | 2021-08-17 |
| CVE-2016-2169 json | Cloud Foundry Cloud Controller, capi-release versions prior to 1.0.0 and cf-release versions prior to v237, contain a busines... | 5.3 - MEDIUM | 2018-04-18 | 2018-05-24 |
Known Affected Configurations (CPE V2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudfoundry | Cloud Controller | 1.91.0 | |||
| Application | Cloudfoundry | Cloud Controller | 1.88.0 | |||
| Application | Cloudfoundry | Cloud Controller | 1.78.0 | |||
| Hardware | Cloudfoundry | Cloud Controller | - |