CVE-2020-5416 - CVE House
Back to Database
Status published High CVE-2020-5416

CF clusters with NGINX in front of them may be vulnerable to DoS

Vulnerability Description

Cloud Foundry Routing (Gorouter), versions prior to 0.204.0, when used in a deployment with NGINX reverse proxies in front of the Gorouters, is potentially vulnerable to denial-of-service attacks in which an unauthenticated malicious attacker can send specially-crafted HTTP requests that may cause the Gorouters to be dropped from the NGINX backend pool.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5416

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cloud Foundry

View all reports →

Affected Software

Routing, CF Deployment
Vulnerable Versions:
All

Timeline

Official Publish: August 21st, 2020
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Weaknesses (CWE)