ZeroHour

CVE-2020-5422

CVSS 3.1
6.5 medium
EPSS
<1%p58
Published
()
Modified
Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Vendors
cloud foundry
Products
bosh system metrics server
Weakness
CWE-214, CWE-668
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.