CVE-2016-2169 describes a business logic flaw in Cloud Foundry Cloud Controller, affecting capi-release versions prior to 1.0.0 and cf-release versions prior to v237. This vulnerability allows an application developer to create an application with a route that conflicts with a platform service route, potentially redirecting traffic intended for the service. Rated with a CVSS score of 5.3 (MEDIUM), this vulnerability has a network attack vector and low attack complexity, but requires no privileges or user interaction. The potential impact is limited to information integrity, as an attacker could intercept traffic, but not necessarily modify or deny service. There is no evidence of active exploitation, nor is exploit code publicly available in Metasploit, Nuclei, or ExploitDB. The vulnerability has received no community discussion or media coverage, indicating a low level of public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.0.0CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:* | ||
< 237CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:cf-release:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.