CVE-2019-11277: Cloudfoundry Cf-Deployment
High severity, CVSS 8.1. EPSS: 1.7% chance of exploitation in the next 30 days.
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
Affected products
- Cloudfoundry Cf-Deployment: before 11.1.0 (fixed in 11.1.0)
- Cloudfoundry Nfs Volume Release: from 1.7.0, before 1.7.11 (fixed in 1.7.11); from 2.0.0, before 2.3.0 (fixed in 2.3.0)
Published 2019-09-23. Last modified 2026-06-17.