CVE-2024-37082

When deploying Cloud Foundry together with the haproxy-boshrelease and using a non default configuration, it might be possible to craft HTTP requests that bypass mTLS authentication to Cloud Foundry applications.  You are affected if you have route-services enabled in routing-release and have configured the haproxy-boshrelease property “ha_proxy.forwarded_client_cert” to “forward_only_if_route_service”.
Configurations

No configuration.

History

No history.

Information

Published : 2024-07-03 06:15

Updated : 2024-07-12 17:15


NVD link : CVE-2024-37082

Mitre link : CVE-2024-37082

CVE.ORG link : CVE-2024-37082


JSON object : View

Products Affected

No product.

CWE
CWE-290

Authentication Bypass by Spoofing