<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Cloud Foundry</title>
	<atom:link href="https://www.cloudfoundry.org/feed/" rel="self" type="application/rss+xml" />
	<link>https://www.cloudfoundry.org/</link>
	<description>The industry standard cloud application platform</description>
	<lastBuildDate>Thu, 27 Aug 2020 18:45:30 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=7.0</generator>
	<item>
		<title>USN-4436-1: librsvg vulnerabilities</title>
		<link>https://www.cloudfoundry.org/usn-4436-1/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Thu, 27 Aug 2020 19:40:41 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=64461</guid>

					<description><![CDATA[<p>USN-4436-1: librsvg vulnerabilities Severity Medium Vendor Canonical Ubuntu Versions Affected Canonical Ubuntu 18.04 Description It was discovered that librsvg incorrectly handled parsing certain SVG files. A remote attacker could possibly use this issue to cause librsvg to crash, resulting in a denial of service. This issue only affected Ubuntu 16.04 LTS. (CVE-2017-11464) It was discovered [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/usn-4436-1/">USN-4436-1: librsvg vulnerabilities</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>USN-4428-1: Python vulnerabilities</title>
		<link>https://www.cloudfoundry.org/usn-4428-1/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Thu, 27 Aug 2020 19:40:38 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=64457</guid>

					<description><![CDATA[<p>USN-4428-1: Python vulnerabilities Severity Medium Vendor Canonical Ubuntu Versions Affected Canonical Ubuntu 14.04 Canonical Ubuntu 16.04 Canonical Ubuntu 18.04 Description It was discovered that Python documentation had a misleading information. A security issue could be possibly caused by wrong assumptions of this information. This issue only affected Ubuntu 12.04 ESM, Ubuntu 14.04 ESM, Ubuntu 16.04 [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/usn-4428-1/">USN-4428-1: Python vulnerabilities</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>USN-4436-2: librsvg regression</title>
		<link>https://www.cloudfoundry.org/usn-4436-2/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Thu, 27 Aug 2020 19:40:23 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=64463</guid>

					<description><![CDATA[<p>USN-4436-2: librsvg regression Severity Unknown Vendor Canonical Ubuntu Versions Affected Canonical Ubuntu 18.04 Description USN-4436-1 fixed a vulnerability in librsvg. The upstream fix caused a regression when parsing certain SVG files. This update backs out the fix pending further investigation. Original advisory details: It was discovered that librsvg incorrectly handled parsing certain SVG files. A [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/usn-4436-2/">USN-4436-2: librsvg regression</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>USN-4431-1: FFmpeg vulnerabilities</title>
		<link>https://www.cloudfoundry.org/usn-4431-1/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Thu, 27 Aug 2020 19:40:10 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=64459</guid>

					<description><![CDATA[<p>USN-4431-1: FFmpeg vulnerabilities Severity Medium Vendor Canonical Ubuntu Versions Affected Canonical Ubuntu 18.04 Description It was discovered that FFmpeg incorrectly verified empty audio packets or HEVC data. An attacker could possibly use this issue to cause a denial of service via a crafted file. This issue only affected Ubuntu 16.04 LTS, as it was already [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/usn-4431-1/">USN-4431-1: FFmpeg vulnerabilities</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CVE-2019-15225/15226: Envoy 1.11.1 vulnerability fixes</title>
		<link>https://www.cloudfoundry.org/cve-2019-15225-15226/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Mon, 11 Nov 2019 18:18:46 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=60073</guid>

					<description><![CDATA[<p>Severity High Vendor Cloud Foundry Foundation Description Cloud Foundry Diego, versions prior to 2.39.0, consumes a vulnerable version of Envoy which is vulnerable to a denial-of-service attack. A remote unauthenticated malicious user may craft requests with a large number of headers to consume excess CPU or may send a request with a very long URI [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/cve-2019-15225-15226/">CVE-2019-15225/15226: Envoy 1.11.1 vulnerability fixes</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
		<item>
		<title>CVE-2019-3801: Java Projects using HTTP to fetch dependencies</title>
		<link>https://www.cloudfoundry.org/cve-2019-3801/</link>
		
		<dc:creator><![CDATA[Cloud Foundry Foundation Security Team]]></dc:creator>
		<pubDate>Mon, 22 Apr 2019 18:54:01 +0000</pubDate>
				<category><![CDATA[Security Advisory]]></category>
		<guid isPermaLink="false">https://www.cloudfoundry.org/?p=56230</guid>

					<description><![CDATA[<p>CVE-2019-3801: Java Projects using HTTP to fetch dependencies Severity High Vendor Cloud Foundry Foundation Affected Cloud Foundry Products and Versions CredHub 2.1 versions prior to 2.1.3 1.9 versions prior to 1.9.10 UAA Release (OSS) All versions prior to v64.0 Description Cloudfoundry java products are using an insecure protocol to fetch dependencies when building. Mitigation Users [&#8230;]</p>
<p>The post <a href="https://www.cloudfoundry.org/cve-2019-3801/">CVE-2019-3801: Java Projects using HTTP to fetch dependencies</a> appeared first on <a href="https://www.cloudfoundry.org">Cloud Foundry</a>.</p>
]]></description>
		
		
		
			</item>
	</channel>
</rss>
