CVE-2022-31733
Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could connect to an application that should be only reachable via mTLS, without presenting a client certificate.
Published:Feb 3, 2023
Last Modified:Mar 25, 2025
EPS:Feb 3, 2023
EPSS Score:0.00124
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Cloudfoundry
Product
Cf-deployment
Cloudfoundry
Cf-deployment
Vendor
Cloudfoundry
Product
Diego
Cloudfoundry
Diego
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
