CVE-2018-1268: Cloudfoundry Loggregator
Medium severity, CVSS 6.8. EPSS: 1% chance of exploitation in the next 30 days.
Cloud Foundry Loggregator, versions 89.x prior to 89.5 or 96.x prior to 96.1 or 99.x prior to 99.1 or 101.x prior to 101.9 or 102.x prior to 102.2, does not validate app GUID structure in requests. A remote authenticated malicious user knowing the GUID of an app may construct malicious requests to read from or write to the logs of that app.
Affected products
- Cloudfoundry Loggregator: from 89, before 89.5 (fixed in 89.5); from 96, before 96.1 (fixed in 96.1); from 99, before 99.1 (fixed in 99.1); from 101, before 101.9 (fixed in 101.9); from 102, before 102.2 (fixed in 102.2)
Published 2018-06-06. Last modified 2026-06-17.