Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-m9cq-wcff-6m72

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.

EPSS

Процентиль: 55%
0.00326
Низкий

Дефекты

CWE-532

Связанные уязвимости

CVSS3: 6.5
nvd
почти 6 лет назад

Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.

EPSS

Процентиль: 55%
0.00326
Низкий

Дефекты

CWE-532