{"id":"CVE-2023-34041","summary":"CVE-2023-34041-Abuse of HTTP Hop-by-Hop Headers in Cloud Foundry Gorouter","details":"Cloud foundry routing release versions prior to 0.278.0 are vulnerable to abuse of HTTP Hop-by-Hop Headers. An unauthenticated attacker can use this vulnerability for headers like B3 or X-B3-SpanID to affect the identification value recorded in the logs in foundations.\n","modified":"2026-08-12T03:51:19.164825492Z","published":"2023-09-08T07:22:00.607Z","database_specific":{"unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"all"},{"fixed":"0.278.0"},{"introduced":"all"},{"fixed":"32.4.0"}]}],"cna_assigner":"vmware","osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34041.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/34xxx/CVE-2023-34041.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-34041"},{"type":"ARTICLE","url":"https://www.cloudfoundry.org/blog/abuse-of-http-hop-by-hop-headers-in-cloud-foundry-gorouter/"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/cf-deployment","events":[{"introduced":"0"},{"fixed":"4a5d79d5298af90a447042f8a1abc7b6242e5693"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"32.4.0"}],"source":"CPE_RANGE","cpe":"cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*"}}],"versions":["v32.3.0","v32.2.0","v32.1.0","v32.0.0","v31.6.0","v31.5.0","v31.4.0","v31.3.0","v31.2.0","v31.1.0","v31.0.0","v30.10.0","v30.9.0","v30.8.0","v30.7.0","v30.6.0","v30.5.0","v30.4.0","v30.3.0","v30.2.0","v30.1.0","v30.0.0","v29.1.0","v29.0.0","v28.2.0","v28.1.0","v28.0.0","v27.8.0","v27.7.0","v27.6.0","v27.5.0","v27.4.0","v27.2.0","v27.1.0","v27.0.0","v26.7.0","v26.6.0","v26.5.0","v26.4.0","v26.3.0","v26.2.0","v26.1.0","v26.0.0","v25.1.0","v25.0.0","v24.7.0","v24.4.0","v24.3.0","v24.2.0","v24.1.0","v24.0.0","v23.5.0","v23.4.0","v23.3.0","v23.2.0","v23.1.0","v22.1.0","v23.0.0","v22.2.0","v22.0.0","v21.11.0","v21.10.0","v21.9.0","v21.8.0","v21.7.0","v21.6.0","v21.5.0","v21.4.0","v21.3.0","v21.2.0","v21.1.0","v21.0.0","v20.4.0","v20.3.0","v20.2.0","v20.1.0","v20.0.0","v19.0.0","v18.0.0","v17.1.0","v17.0.0","v16.25.0","v16.24.0","v16.23.0","v16.21.0","v16.22.0","v16.20.0","v16.19.0","v16.18.0","v16.17.0","v16.16.0","v16.15.0","v16.14.0","v16.13.0","v16.12.0","v16.11.0","v16.10.0","v16.9.0","v16.8.0","v16.7.0","v16.6.0","v16.5.0","v16.4.0","v16.3.0","v16.2.0","v16.1.0","v16.0.0","v15.7.0","v15.6.0","v15.5.0","v15.4.0","v15.3.0","v15.2.0","v15.1.0","v15.0.0","v14.0.0","v13.23.0","v13.22.0","v13.21.0","v13.20.0","v13.19.0","v13.18.0","v13.17.0","v13.16.0","v13.15.0","v13.14.0","v13.13.0","v13.12.0","v13.11.0","v13.10.0","v13.9.0","v13.8.0","v13.7.0","v13.6.0","v13.5.0","v13.4.0","v13.3.0","v13.2.0","v13.1.0","v13.0.0","v12.45.0","v12.44.0","v12.43.0","v12.42.0","v12.41.0","v12.40.0","v12.39.0","v12.38.0","v12.37.0","v12.36.0","v12.35.0","v12.34.0","v12.33.0","v12.32.0","v12.31.0","v12.30.0","v12.29.0","v12.28.0","v12.27.0","v12.26.0","v12.25.0","v12.24.0","v12.23.0","v12.22.0","v12.21.0","v12.20.0","v12.19.0","v12.18.0","v12.17.0","v12.16.0","v12.15.0","v12.14.0","v12.13.0","v12.12.0","v12.11.0","v12.10.0","v12.9.0","v12.8.0","v12.7.0","v12.6.0","v12.5.0","v12.4.0","v12.3.0","v12.2.0","v12.1.0","v12.0.0","v11.2.0","v11.1.0","v11.0.0","v10.1.0","v10.0.0","v7.9.0","v7.8.0","v7.6.0","v7.5.0","v7.4.0","v7.3.0","v7.2.0","v7.1.0","v7.0.0","v6.10.0","v6.9.0","v6.8.0","v6.7.0","v6.6.0","v6.5.0","v6.4.0","v6.3.0","v6.2.0","v6.1.0","v6.0.0","v5.5.0","v5.4.0","v5.3.0","v5.1.0","v5.0.0","v4.5.0","v4.4.0","v4.3.0","v4.2.0","v4.1.0","v4.0.0","v3.6.0","v3.5.0","v3.4.0","v3.3.0","v3.2.0","v3.1.0","v3.0.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.0","v1.38.0","v1.37.0","v1.36.0","v1.35.0","v1.34.0","v1.33.0","v1.32.0","v1.31.0","v1.30.0","v1.29.0","v1.28.0","v1.27.0","v1.26.0","v1.25.0","v1.24.0","v1.23.0","v1.22.0","v1.21.0","v1.20.0","v1.19.0","v1.18.0","v1.16.0","v1.17.0","v1.15.0","v1.14.0","v1.13.0","v1.12.0","v1.11.0","v1.10.0","v1.9.0","v1.8.0","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.2.0","v1.1.0","v0.37.0","v1.0.0","v0.36.0","v0.35.0","v0.34.0","v0.33.0","v0.32.0","v0.31.0","v0.30.0","v0.28.0","v0.29.0","v0.15.0","v0.13.0","v0.14.0","v0.12.0","v0.11.0","v0.10.0","v0.9.1","v0.9.0","v0.8.0","v0.3.0","v0.7.0","v0.5.0","v0.2.1","v0.2.2","v0.2.0","v0.1.0","v0.0.2","v0.0.1","v0.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34041.json"}},{"ranges":[{"type":"GIT","repo":"https://github.com/cloudfoundry/routing-release","events":[{"introduced":"0"},{"fixed":"cd8b68332d12134bbedca8a80744a4a2ba2e4984"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:cloudfoundry:routing-release:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"0.278.0"}]}}],"versions":["v0.277.0","v0.276.0","v0.275.0","v0.273.0","v0.272.0","v0.271.0","v0.270.0","v0.269.0","v0.268.0","v0.265.1","v0.264.0","v0.263.0","v0.262.0","v0.261.0","v0.260.0","v0.259.0","v0.258.0","0.258.0","v0.0.0","v0.257.0","0.257.0","v0.256.0","0.256.0","v0.255.0","0.255.0","v0.254.0","0.254.0","0.253.0","v0.253.0","v0.252.0","0.252.0","v0.251.0","0.251.0","v0.250.0","0.250.0","0.249.0","v0.249.0","v0.248.0","0.248.0","v0.245.0","0.245.0","v0.247.0","0.247.0","v0.246.0","0.246.0","0.236.0","v0.244.0","0.244.0","v0.243.0","0.243.0","v0.242.0","0.242.0","v0.241.0","0.241.0","v0.240.0","0.239.0","v0.239.0","v0.238.0","0.238.0","v0.237.0","0.237.0","v0.236.0","0.235.0","0.234.0","0.233.0","0.232.0","0.231.0","0.230.0","0.229.0","0.228.0","0.227.0","0.226.0","0.225.0","0.224.0","0.223.0","0.222.0","0.221.0","0.220.0","0.219.0","0.218.0","0.216.0","0.215.0","0.214.0","0.213.0","0.212.0","0.211.0","0.210.0","0.209.0","0.208.0","0.207.0","0.206.0","0.205.0","0.204.0","0.203.0","0.202.0","0.201.0","0.200.0","0.199.0","0.196.0","0.195.0","0.194.0","0.192.0","0.187.0","0.186.0","0.184.0","0.183.0","0.180.0","0.179.0","0.178.0","0.176.0","0.175.0","0.174.0","0.173.0","0.172.0","0.171.0","0.166.0","0.162.0","0.160.0","0.157.0","0.154.0","0.147.0","0.142.0","0.137.0","0.136.0","0.134.0","0.123.0","0.121.0","0.118.0","0.99.0","0.69.0","0.66.0","0.62.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-34041.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N"}]}