Starting with diego-release 2.55.0 and up to 2.69.0, and starting with CF Deployment 17.1 and up to 23.2.0, apps are accessible via another port on diego cells, allowing application ingress without a client certificate. If mTLS route integrity is enabled AND unproxied ports are turned off, then an attacker could connect to an application that should be only reachable via mTLS, without presenting a client certificate.
Metrics
Affected Vendors & Products
References
History
Tue, 25 Mar 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|

Status: PUBLISHED
Assigner: vmware
Published: 2023-02-03T00:00:00.000Z
Updated: 2025-03-25T19:11:41.312Z
Reserved: 2022-05-25T00:00:00.000Z
Link: CVE-2022-31733

Updated: 2024-08-03T07:26:01.290Z

Status : Modified
Published: 2023-02-03T19:15:11.107
Modified: 2025-03-25T20:15:13.693
Link: CVE-2022-31733

No data.