Cloud Foundry routing release versions from v0.163.0 to v0.283.0 are vulnerable to a DOS attack. An unauthenticated attacker can use this vulnerability to force route pruning and therefore degrade the service availability of the Cloud Foundry deployment.
The product does not properly control the allocation and maintenance of a limited resource.
Link | Tags |
---|---|
https://www.cloudfoundry.org/blog/cve-2023-34061-gorouter-route-pruning/ | vendor advisory |