Vulnerability Details CVE-2020-5401
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 62.6%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-5401
-
cpe:2.3:a:cloudfoundry:routing_release:0.118.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.121.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.122.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.123.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.126.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.133.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.134.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.135.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.136.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.137.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.138.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.139.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.140.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.141.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.142.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.143.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.144.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.144.1
-
cpe:2.3:a:cloudfoundry:routing_release:0.145.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.146.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.147.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.149.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.150.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.151.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.152.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.153.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.154.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.155.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.156.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.157.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.158.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.159.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.160.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.161.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.162.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.163.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.164.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.165.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.166.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.167.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.168.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.169.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.170.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.171.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.172.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.173.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.174.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.175.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.176.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.177.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.178.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.179.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.180.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.181.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.182.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.183.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.184.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.185.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.186.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.187.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.188.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.62.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.66.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.69.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.99.0