PT-2017-8645 · Cloud Foundry Foundation · Cloud Foundry

Publicado

2017-05-02

·

Atualizado

2017-05-11

·

CVE-2016-5006

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry versions prior to 239
Description The issue allows attackers to obtain sensitive user credential information. This is due to the Cloud Controller logging user-provided service objects at creation.
Recommendations For versions prior to 239, update to version 239 or later to resolve the issue.

Correção

Information Disclosure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2016-5006

Produtos afetados

Cloud Foundry