SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-22100

In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible.

MEDIUM 5.3EPSS 0.92%

Does this matter?

Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.

Description

In cloud foundry CAPI versions prior to 1.122, a denial-of-service attack in which a developer can push a service broker that (accidentally or maliciously) causes CC instances to timeout and fail is possible. An attacker can leverage this vulnerability to cause an inability for anyone to push or manage apps.

CVSS 3.1
5.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
EPSS
0.92% probability · 58th percentile
CISA KEV
Not listed
Weakness
CWE-400
Affected
cloudfoundry/capi-release · cloudfoundry/cf-deployment
Source
security@vmware.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.