Vulnerability Details CVE-2019-11289
Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.3%
CVSS Severity
CVSS v3 Score 8.6
CVSS v2 Score 7.8
Products affected by CVE-2019-11289
-
cpe:2.3:a:cloudfoundry:cf-deployment:-
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.0.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.2.2
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.27.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.28.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.29.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.30.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.31.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.32.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.33.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.34.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.35.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.36.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.37.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:0.9.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.12.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.13.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.14.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.15.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.16.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.17.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.18.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.19.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.20.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.21.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.22.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.23.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.24.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.25.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.26.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.27.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.28.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.29.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.3.1
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.30.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.31.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.32.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.33.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.34.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.35.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.36.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.37.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.38.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.39.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.40.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:1.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:10.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:10.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:11.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:11.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:11.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:12.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:2.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:3.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:4.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:5.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:6.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.10.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.11.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.5.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.6.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.7.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.8.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:7.9.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:8.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:8.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.0.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.1.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.2.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.3.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.4.0
-
cpe:2.3:a:cloudfoundry:cf-deployment:9.5.0
-
cpe:2.3:a:cloudfoundry:routing-release:-
-
cpe:2.3:a:cloudfoundry:routing-release:0.118.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.121.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.122.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.123.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.126.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.133.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.134.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.135.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.136.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.137.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.138.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.139.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.140.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.141.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.142.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.143.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.144.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.144.1
-
cpe:2.3:a:cloudfoundry:routing-release:0.145.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.146.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.147.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.149.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.150.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.151.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.152.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.153.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.154.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.155.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.156.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.157.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.158.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.159.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.160.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.161.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.162.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.163.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.164.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.165.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.166.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.167.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.168.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.169.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.170.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.171.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.172.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.173.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.174.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.175.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.176.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.177.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.178.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.179.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.180.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.181.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.182.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.183.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.184.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.185.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.186.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.187.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.188.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.189.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.190.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.191.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.192.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.62.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.66.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.69.0
-
cpe:2.3:a:cloudfoundry:routing-release:0.99.0