ZeroHour

CVE-2020-5399

CVSS 3.1
7.4 high
EPSS
<1%p43
Published
()
Modified
Description

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.

Vendors
cloudfoundrypivotal software
Products
credhub, cloud foundry cf-deployment
Weakness
CWE-319
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.