ZeroHour

CVE-2020-5400

CVSS 3.1
6.5 medium
EPSS
<1%p53
Published
()
Modified
Description

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.

Vendors
cloudfoundry
Products
capi-release, cf-deployment
Weakness
CWE-522, CWE-532
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.