CVE-2022-31733 - CVE House
Back to Database
Status published Unknown CVE-2022-31733

Starting with diego-release 2.55.0 and up to 2.69.0, and starting...

Vulnerability Description

Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could connect to an application that should be only reachable via mTLS, without presenting a client certificate.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-31733

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Cloud Foundry Diego and CF Deployment
Vulnerable Versions:
Affected versions of Diego are all versions between 2.55.0 and 2.69.0 (inclusive) and affected versions of CF Deployment are all versions between 17.1 and 23.2.0 (inclusive).

Timeline

Official Publish: February 3rd, 2023
Last Modified: March 25th, 2025
Added to House: July 21st, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.