|
[LOW] CVE-2016-6637 UAA CSRF Vulnerability for OAuth Approvals
CVE-2016-6637 UAA CSRF Vulnerability for OAuth Approvals
Severity
Low
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v241 and earlier versions
-
UAA release
CVE-2016-6637 UAA CSRF Vulnerability for OAuth Approvals
Severity
Low
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v241 and earlier versions
-
UAA release
|
By
Molly Crowther
·
#5769
·
|
|
[MEDIUM] CVE-2016-6636 UAA Open Redirect Vulnerability for Subdomains
CVE-2016-6636 UAA Open Redirect Vulnerability for Subdomains
Severity
Medium
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v241 and earlier versions
-
UAA
CVE-2016-6636 UAA Open Redirect Vulnerability for Subdomains
Severity
Medium
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v241 and earlier versions
-
UAA
|
By
Molly Crowther
·
#5768
·
|
|
[HIGH] CVE-2016-6651: Privilege Escalation in UAA
CVE-2016-6651: Privilege Escalation in UAA
Severity
High
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v242 and earlier versions
-
UAA release v3.7.0 &
CVE-2016-6651: Privilege Escalation in UAA
Severity
High
Vendor
Cloud Foundry Foundation
Versions Affected
-
Cloud Foundry release v242 and earlier versions
-
UAA release v3.7.0 &
|
By
Molly Crowther
·
#5767
·
|
|
Re: FW: issue tracker permissions
Hi all -- a couple people reached out asking for a date for Viewers can
follow. We are currently targeting November of this year.
Thanks,
Lisa
Hi all -- a couple people reached out asking for a date for Viewers can
follow. We are currently targeting November of this year.
Thanks,
Lisa
|
By
Lisa Doan <ldoan@...>
·
#5766
·
|
|
Re: FW: issue tracker permissions
Hi all,
Just to re-iterate, we do have this feature prioritized on the Tracker
team. I'm sorry we haven't been able to deliver this yet, but there are a
number of other higher priority items that we
Hi all,
Just to re-iterate, we do have this feature prioritized on the Tracker
team. I'm sorry we haven't been able to deliver this yet, but there are a
number of other higher priority items that we
|
By
Lisa Doan <ldoan@...>
·
#5765
·
|
|
Re: FW: issue tracker permissions
Guillaume,
thank you so much! One beer at the next CF summit is on me. :)
Carlo
Guillaume,
thank you so much! One beer at the next CF summit is on me. :)
Carlo
|
By
Carlo Alberto Ferraris
·
#5764
·
|
|
Re: [ANN] Utilities PMC projects graduating from incubation
Thanks Mike and CF Community.
We would like to invite the attendees at CF Summit Europe this week to learn more about .NET tools integration and scenarios these project enables.
Please join the
Thanks Mike and CF Community.
We would like to invite the attendees at CF Summit Europe this week to learn more about .NET tools integration and scenarios these project enables.
Please join the
|
By
Shah, Harshit
·
#5763
·
|
|
Re: [ANN] Utilities PMC projects graduating from incubation
Thanks HPE!
By
Dr Nic Williams <drnicwilliams@...>
·
#5762
·
|
|
[ANN] Utilities PMC projects graduating from incubation
Hi all,
In May 2015, the Utilities PMC began incubating a handful of .NET developer
tools created and maintained by engineers at HPE.
These projects have been maintained by HPE over the last 16
Hi all,
In May 2015, the Utilities PMC began incubating a handful of .NET developer
tools created and maintained by engineers at HPE.
These projects have been maintained by HPE over the last 16
|
By
Mike Dalessio
·
#5761
·
|
|
Re: FW: issue tracker permissions
Dear Guillaume,
Thanks for your efforts in this direction. As I already stated before, it is really a pain that you are not able to follow stories or comment when not being a member in a
Dear Guillaume,
Thanks for your efforts in this direction. As I already stated before, it is really a pain that you are not able to follow stories or comment when not being a member in a
|
By
Marco Voelz
·
#5760
·
|
|
Re: FW: issue tracker permissions
Hi,
The mirroring of foundation projects is around 60% complete. See [5] for
more detailed coverage. This should enable community members to watch the
most active foundation backlogs. I received no
Hi,
The mirroring of foundation projects is around 60% complete. See [5] for
more detailed coverage. This should enable community members to watch the
most active foundation backlogs. I received no
|
By
Guillaume Berche
·
#5759
·
|
|
CF CLI v6.22.0 and v6.22.1 Released
The CF CLI team just cut 6.22.1. Ignore 6.22.0.
Binaries and link to release notes are available at:
https://github.com/cloudfoundry/cli#downloads
Improved help pages
The cf help page now lists
The CF CLI team just cut 6.22.1. Ignore 6.22.0.
Binaries and link to release notes are available at:
https://github.com/cloudfoundry/cli#downloads
Improved help pages
The cf help page now lists
|
By
Koper, Dies <diesk@...>
·
#5758
·
|
|
Re: OpenSSL CVE
As you may have heard, Canonical released a regression USN (
http://www.ubuntu.com/usn/usn-3087-2/) to cover an issue introduced in the
fix released yesterday
As you may have heard, Canonical released a regression USN (
http://www.ubuntu.com/usn/usn-3087-2/) to cover an issue introduced in the
fix released yesterday
|
By
Molly Crowther
·
#5757
·
|
|
OpenSSL CVE
Hello All,
If you get questions about the recent SSL CVE today - it is a high and the
BOSH team will be acting on it as soon as we have an Ubuntu update from
Canonical. I will reply with new stemcell
Hello All,
If you get questions about the recent SSL CVE today - it is a high and the
BOSH team will be acting on it as soon as we have an Ubuntu update from
Canonical. I will reply with new stemcell
|
By
Molly Crowther
·
#5756
·
|
|
how can i connect doppler(firehose) with doppler vm's IP?
I have test noaa's sample to collect metrics from doppler firehose.
When i set "DOPPLER_ADDR" to "wss://doppler.bosh-lite.com:443", it worked well.
I just wondering if it is possible to connect
I have test noaa's sample to collect metrics from doppler firehose.
When i set "DOPPLER_ADDR" to "wss://doppler.bosh-lite.com:443", it worked well.
I just wondering if it is possible to connect
|
By
inho cho
·
#5755
·
|
|
Re: SSL termination for private domains
Ha, just for fun we detailed how you could, technically, request a
letsencrypt cert via a CF app :-) [1]
I would agree that a user would like the ability to auto-renew certs, if
they are currently
Ha, just for fun we detailed how you could, technically, request a
letsencrypt cert via a CF app :-) [1]
I would agree that a user would like the ability to auto-renew certs, if
they are currently
|
By
James Leavers
·
#5754
·
|
|
Re: SSL termination for private domains
Yes, it's the protocol[1] proposed by ISRG letsencrypt[2] (under the linux foundation umbrella) that allows automated generation and PKI signing of TLS certificates.
For the record, there's a go
Yes, it's the protocol[1] proposed by ISRG letsencrypt[2] (under the linux foundation umbrella) that allows automated generation and PKI signing of TLS certificates.
For the record, there's a go
|
By
Carlo Alberto Ferraris
·
#5753
·
|
|
Re: SSL termination for private domains
Our current policy to our users is SNI by default, i.e. unless they explicitly require non-SNI TLS termination they get SNI termination. We went with this because browser support seems good[1] and
Our current policy to our users is SNI by default, i.e. unless they explicitly require non-SNI TLS termination they get SNI termination. We went with this because browser support seems good[1] and
|
By
Carlo Alberto Ferraris
·
#5752
·
|
|
Re: SSL termination for private domains
Thank you all for your responses.
A follow up question: for the gorouter to host certs for multiple domains,
it seems only natural that it would do this via SNI. Is client support for
SNI ubiquitous
Thank you all for your responses.
A follow up question: for the gorouter to host certs for multiple domains,
it seems only natural that it would do this via SNI. Is client support for
SNI ubiquitous
|
By
Shannon Coen
·
#5751
·
|
|
Re: SSL termination for private domains
carlo.ferraris(a)rakuten.com> wrote:
Wasn't familiar with ACME until I just googled it. Do you mean some
mechanism for automated generation of certs?
carlo.ferraris(a)rakuten.com> wrote:
Wasn't familiar with ACME until I just googled it. Do you mean some
mechanism for automated generation of certs?
|
By
Shannon Coen
·
#5750
·
|