CVE-2019-11289 - CVE House
Back to Database
Status published High CVE-2019-11289

A forged route service request using an invalid nonce can cause the gorouter to panic and crash

Vulnerability Description

Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-11289

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cloud Foundry

View all reports →

Affected Software

Routing
Vulnerable Versions:
All

Timeline

Official Publish: November 19th, 2019
Last Modified: September 16th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)