PT-2020-18477 · Mysql Server+1 · Mysql Server+1

Published

2020-11-11

·

Updated

2020-12-01

·

CVE-2020-5426

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Scheduler for TAS versions prior to 1.4.0
Description The issue allows plaintext transmission of a UAA client token over a non-TLS connection, which depends on the configuration of the MySQL server used to cache the token. If the token is intercepted, it can provide an attacker with admin-level access in the cloud controller.
Recommendations For versions prior to 1.4.0, update to version 1.4.0 or later to resolve the issue. As a temporary workaround, consider configuring the MySQL server to use a secure connection or restricting access to the UAA client token to minimize the risk of exploitation.

Fix

Cleartext Transmission of Sensitive Information

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5426

Affected Products

Mysql Server
Scheduler For Tas