Vulnerability Details CVE-2020-5401
Cloud Foundry Routing Release, versions prior to 0.197.0, contains GoRouter, which allows malicious clients to send invalid headers, causing caching layers to reject subsequent legitimate clients trying to access the app.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.003
EPSS Ranking 54.6%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 5.0
Products affected by CVE-2020-5401
-
cpe:2.3:a:cloudfoundry:routing_release:0.118.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.121.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.122.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.123.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.126.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.133.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.134.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.135.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.136.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.137.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.138.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.139.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.140.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.141.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.142.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.143.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.144.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.144.1
-
cpe:2.3:a:cloudfoundry:routing_release:0.145.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.146.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.147.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.149.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.150.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.151.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.152.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.153.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.154.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.155.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.156.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.157.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.158.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.159.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.160.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.161.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.162.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.163.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.164.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.165.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.166.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.167.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.168.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.169.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.170.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.171.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.172.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.173.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.174.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.175.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.176.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.177.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.178.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.179.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.180.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.181.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.182.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.183.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.184.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.185.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.186.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.187.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.188.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.62.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.66.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.69.0
-
cpe:2.3:a:cloudfoundry:routing_release:0.99.0