CVE-2020-5401 describes a denial-of-service vulnerability in Cloud Foundry Routing Release versions prior to 0.197.0, specifically impacting the GoRouter component. Malicious clients can send invalid headers, leading to caching layers rejecting legitimate requests for applications. This vulnerability has a CVSS score of 5.3 (Medium), indicating a low-complexity attack that can be executed remotely without authentication, resulting in a denial of service. There is no evidence of active exploitation, nor are there known public exploits or Metasploit modules available. Community discussion is minimal, with only one Reddit mention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.197.0CPE matchmatch criteria | cpe:2.3:a:cloudfoundry:routing_release:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.