CVE-2024-22279

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-22279
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-22279.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-22279
Published
2024-06-10T20:15:12.880Z
Modified
2025-12-08T07:52:49.588515Z
Severity
  • 7.5 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H CVSS Calculator
Summary
[none]
Details

Improper handling of requests in Routing Release > v0.273.0 and <= v0.297.0 allows an unauthenticated attacker to degrade the service availability of the Cloud Foundry deployment if performed at scale.

References

Affected packages

Git / github.com/cloudfoundry/cf-deployment

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/cf-deployment
Events

Affected versions

v30.*

v30.10.0
v30.9.0

v31.*

v31.0.0
v31.1.0
v31.2.0
v31.3.0
v31.4.0
v31.5.0
v31.6.0

v32.*

v32.0.0
v32.1.0
v32.10.0
v32.11.0
v32.12.0
v32.13.0
v32.14.0
v32.15.0
v32.16.0
v32.17.0
v32.2.0
v32.3.0
v32.4.0
v32.5.0
v32.6.0
v32.7.0
v32.8.0
v32.9.0

v33.*

v33.0.0
v33.1.0
v33.10.0
v33.11.0
v33.12.0
v33.2.0
v33.3.0
v33.4.0
v33.5.0
v33.6.0
v33.7.0
v33.8.0
v33.9.0

v34.*

v34.0.0
v34.1.0
v34.2.0

v35.*

v35.0.0
v35.1.0
v35.2.0
v35.3.0
v35.4.0
v35.5.0

v36.*

v36.0.0

v37.*

v37.0.0
v37.1.0
v37.2.0
v37.3.0
v37.4.0
v37.5.0

v38.*

v38.0.0
v38.1.0

v39.*

v39.0.0
v39.1.0
v39.2.0
v39.3.0
v39.4.0
v39.5.0
v39.6.0
v39.7.0
v39.8.0

v40.*

v40.0.0
v40.1.0
v40.10.0
v40.11.0
v40.12.0
v40.13.0
v40.2.0
v40.3.0
v40.4.0
v40.5.0
v40.6.0
v40.7.0
v40.8.0
v40.9.0

Git / github.com/cloudfoundry/routing-release

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/routing-release
Events

Affected versions

v0.*

v0.273.0
v0.274.0
v0.275.0
v0.276.0
v0.277.0
v0.278.0
v0.279.0
v0.280.0
v0.281.0
v0.282.0
v0.283.0
v0.284.0
v0.285.0
v0.286.0
v0.287.0
v0.288.0
v0.289.0
v0.290.0
v0.291.0
v0.292.0
v0.293.0
v0.294.0
v0.295.0
v0.296.0
v0.297.0