Diego
This hub aggregates every CVE we track for Diego, a product in the cloud saas space. Use it to gauge the current risk picture and drill into individual advisories.
3
CVEs tracked
1
Critical
2
High
0
In CISA KEV
Severity distribution
HIGH2CRITICAL1
Monthly trend
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 3 most recently published vulnerabilities affecting Diego.
- CVE-2022-31733Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without...9.1
- CVE-2018-1265Cloud Foundry Diego, release versions prior to 2.8.0, does not properly sanitize file paths in tar and zip files headers. A remote attacker with CF admin privileges can upload a malicious buildpack...7.2
- CVE-2016-3091Cloud Foundry Diego 0.1468.0 through 0.1470.0 allows remote attackers to cause a denial of service.7.5
Product normalization is registry-driven with AI assist and human review. How it works