Loading HuntDB...

GHSA-2mjv-62fw-hvv4

GitHub Security Advisory

⚠ Unreviewed MODERATE Has CVE

Advisory Details

An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creating subdomains to an already existing route that belongs to a different user in a different org and space, aka an "Application Subdomain Takeover."

Related CVEs

Key Information

GHSA ID
GHSA-2mjv-62fw-hvv4
Published
May 13, 2022 1:10 AM
Last Modified
April 20, 2025 3:49 AM
CVSS Score
5.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: September 29, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.