CVE-2019-11277
Cloud Foundry NFS Volume Service, 1.7.x versions prior to 1.7.11 and 2.x versions prior to 2.3.0, is vulnerable to LDAP injection. A remote authenticated malicious space developer can potentially inject LDAP filters via service instance creation, facilitating the malicious space developer to deny service or perform a dictionary attack.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.4
- CVSS vector
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:L
- EPSS probability
- 0.88%
- CWE
- CWE-90
- Published
- 2019-09-23
- Last modified
- 2026-03-14
Affected products
- Cloud Foundry CF NFS volume release
- Cloud Foundry CF NFS volume release
- Cloud Foundry CF Deployment
Weakness type
Related vulnerabilities
- CVE-2024-56841 — A vulnerability has been identified in Mendix LDAP (All versions < V1.1.2). Affected versions of the module are vulnerab
- CVE-2026-33289 — SuiterCRM has LDAP Filter Injection in Authentication Module
- CVE-2021-41232 — Improper Neutralization of Special Elements used in an LDAP Query
- CVE-2026-46619 — OpenAM Authentication Bypass via MSISDN LDAP Injection
- CVE-2023-28853 — Mastodon's blind LDAP injection in login allows the attacker to leak arbitrary attributes from LDAP database
- CVE-2020-5246 — LDAP injection vulnerability in Traccar GPS Tracking System
- CVE-2023-29050 — The optional "LDAP contacts provider" could be abused by privileged users to inject LDAP filter strings that allow to ac
- CVE-2026-41919 — Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elements in DN Construction