PT-2019-12229 · Cloud Foundry · Cloud Foundry Nfs Volume

Publicado

2019-10-23

·

Atualizado

2021-08-17

·

CVE-2019-11283

CVSS v3.1

8.8

Alta

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry SMB Volume versions prior to v2.0.3
Description The issue accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
Recommendations For versions prior to v2.0.3, update to version v2.0.3 or later to resolve the issue.

Correção

Insertion into Log File

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-11283

Produtos afetados

Cloud Foundry Nfs Volume