GHSA-2mjv-62fw-hvv4
GitHub Security Advisory
⚠ Unreviewed
MODERATE
Has CVE
Advisory Details
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover."
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: September 29, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.