CVE-2016-2165
Last modified
CVE-2016-2165 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
The Loggregator Traffic Controller endpoints in cf-release v231 and lower, Pivotal Elastic Runtime versions prior to 1.5.19 AND 1.6.x versions prior to 1.6.20 are not cleansing request URL paths when they are invalid and are returning them in the 404 response. This could allow malicious scripts to be written directly into the 404 response.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cloudfoundry | Cf-Release | <= 231 |
| Pivotal Software | Cloud Foundry Elastic Runtime | <= 1.5.18 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.0 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.1 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.2 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.3 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.4 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.5 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.6 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.7 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.8 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.9 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.10 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.11 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.12 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.13 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.14 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.15 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.16 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.17 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.18 |
| Pivotal Software | Cloud Foundry Elastic Runtime | 1.6.19 |
References
- https://pivotal.io/security/cve-2016-2165Vendor Advisory
- https://pivotal.io/security/cve-2016-2165Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2016-2165?
How severe is CVE-2016-2165?
How do I fix CVE-2016-2165?
Are you affected by CVE-2016-2165?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
