Spoofing attack in Routing Release and CF Deployment - CVE-2020-5401

 

Spoofing attack in Routing Release and CF Deployment - CVE-2020-5401

Published: February 25, 2020


Vulnerability identifier: #VU25577
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5401
CWE-ID: CWE-451
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform spoofing attack.

The vulnerability exists due to incorrect processing of user-supplied data in GoRouter. A remote attacker can spoof page content, send invalid headers and cause caching layers to reject subsequent legitimate clients trying to access the app.


Affected software

Routing Release
CF Deployment

How to mitigate CVE-2020-5401

Install updates from vendor's website.

Routing Release - update to 0.197.0
CF Deployment - update to 12.27.0

External References

Related Security Bulletins