Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-75vm-6gpr-f398

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.

EPSS

Процентиль: 68%
0.00567
Низкий

Связанные уязвимости

CVSS3: 6.5
nvd
около 6 лет назад

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.

EPSS

Процентиль: 68%
0.00567
Низкий