Cloud Foundry Routing, all versions before 0.193.0, does not properly validate nonce input. A remote unauthenticated malicious user could forge an HTTP route service request using an invalid nonce that will cause the Gorouter to crash.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| code.cloudfoundry.org/gorouter(Go) | 0 | 0.0.0-20191101214924-b1b5c44e050f | N/A |
CVSS Metrics