VDB

CVE-2022-31733

CVE-2022-31733 PUBLISHED CVSS 9.100000381469727 CRITICAL

Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could connect to an application that should be only reachable via mTLS, without presenting a client certificate.

EPSS 0.38% · 30.5th percentile

Risk Scores

CVSS 3.1
9.100000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS Score
0.38%
30.5th percentile

Affected Products

VendorProductVersions
cloudfoundrydiego2.55.0
cloudfoundrycf-deployment17.1
n/aCloud Foundry Diego and CF DeploymentAffected versions of Diego are all versions between 2.55.0 and 2.69.0 (inclusive) and affected versions of CF Deployment are all versions between 17.1 and 23.2.0 (inclusive).

Timeline

  • Feb 3, 2023 CVE Published
  • Feb 4, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Mar 16, 2023 EPSS Score
  • Apr 25, 2023 EPSS Score
  • Jun 4, 2023 EPSS Score
  • Jul 14, 2023 EPSS Score
  • Aug 23, 2023 EPSS Score
  • Oct 2, 2023 EPSS Score
  • Nov 11, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
  • Jan 31, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›