CVE-2020-5401

Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
Configurations

Configuration 1 (hide)

cpe:2.3:a:cloudfoundry:routing_release:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:34

Type Values Removed Values Added
References () https://www.cloudfoundry.org/blog/cve-2020-5401 - Vendor Advisory () https://www.cloudfoundry.org/blog/cve-2020-5401 - Vendor Advisory

Information

Published : 2020-02-27 20:15

Updated : 2024-11-21 05:34


NVD link : CVE-2020-5401

Mitre link : CVE-2020-5401

CVE.ORG link : CVE-2020-5401


JSON object : View

Products Affected

cloudfoundry

  • routing_release
CWE
CWE-393

Return of Wrong Status Code

CWE-444

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')