ZeroHour

CVE-2021-22115

CVSS 3.1
6.5 medium
EPSS
<1%p56
Published
()
Modified
Description

Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller.

Vendors
cloudfoundry
Products
capi-release, cf-deployment
Weakness
CWE-522
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.