Vulnerability Description
Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudfoundry | Cf-Deployment | < 32.4.0 |
| Cloudfoundry | Routing-Release | < 0.278.0 |
References
- https://www.cloudfoundry.org/blog/abuse-of-http-hop-by-hop-headers-in-cloud-founVendor Advisory
- https://www.cloudfoundry.org/blog/abuse-of-http-hop-by-hop-headers-in-cloud-founVendor Advisory
FAQ
What is CVE-2023-34041?
CVE-2023-34041 is a vulnerability with a CVSS score of 5.3 (MEDIUM). Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to...
How severe is CVE-2023-34041?
CVE-2023-34041 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-34041?
Check the references section above for vendor advisories and patch information. Affected products include: Cloudfoundry Cf-Deployment, Cloudfoundry Routing-Release.