Fiche vulnérabilité
CVE-2021-22101 : faille élevée cloudfoundry capi-release (CVSS 7.5)
Description
Cloud Controller versions prior to 1.118.0 are vulnerable to unauthenticated denial of Service(DoS) vulnerability allowing unauthenticated attackers to cause denial of service by using REST HTTP requests with label_selectors on multiple V3 endpoints by generating an enormous SQL query.
En bref
- Sévérité
- Élevée (CVSS 7.5)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 27 oct. 2021
- Dernière mise à jour
- 17 juin 2026
Produits concernés
- cloudfoundry capi-release
- cloudfoundry cf-deployment