CVE Database
/

CVE-2018-1193

Back to search

CVE-2018-1193

Published: May 23, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.

VendorProductVersions

Cloud Foundry

Cloud Foundry Router

affected
versions prior to 0.175.0

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now