PT-2019-12229 · Cloud Foundry · Cloud Foundry Nfs Volume

Published

2019-10-23

·

Updated

2021-08-17

·

CVE-2019-11283

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Cloud Foundry SMB Volume versions prior to v2.0.3
Description The issue accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
Recommendations For versions prior to v2.0.3, update to version v2.0.3 or later to resolve the issue.

Fix

Insertion into Log File

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-11283

Affected Products

Cloud Foundry Nfs Volume