ZeroHour

CVE-2016-0898

CVSS 3.1
10.0 critical
EPSS
1%p71
Published
()
Modified
Description

MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.

Vendors
vmware
Products
pivotal software mysql
Weakness
CWE-255, CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.