Generated remediation guidance and an executive summary. No account required.
Cloud Foundry Routing Release, all versions prior to 0.188.0, contains a vulnerability that can hijack the traffic to route services hosted outside the platform. A user with space developer permissions can create a private domain that shadows the external domain of the route service, and map that route to an app. When the gorouter receives traffic destined for the external route service, this traffic will instead be directed to the internal app using the shadow route.
Use CWE-840, Cloudfoundry vendor hub and Routing Release product page to widen CVE-2019-3789 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2024-22279, CVE-2023-20882 and CVE-2020-5401 for nearby disclosures in the same product family.