CVE-2016-0780: Cloudfoundry Cf-Release
High severity, CVSS 7.5. EPSS: 1.2% chance of exploitation in the next 30 days.
It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attacker could use an improper disk quota value to bypass enforcement and consume all the disk on DEAs/CELLs causing a potential denial of service for other applications.
Affected products
- Cloudfoundry Cf-Release: version 231 only
- Pivotal Software Cloud Foundry Elastic Runtime: version 1.5.0 only; version 1.5.1 only; version 1.5.2 only; version 1.5.3 only; version 1.5.4 only; version 1.5.5 only; …
Published 2017-05-25. Last modified 2026-06-17.