Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q96c-r8j3-g2qp

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.

EPSS

Процентиль: 36%
0.00152
Низкий

8.8 High

CVSS3

Дефекты

CWE-200

Связанные уязвимости

CVSS3: 8.8
nvd
почти 7 лет назад

Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.

suse-cvrf
больше 6 лет назад

Security update for cf-cli

suse-cvrf
больше 6 лет назад

Security update for cf-cli

EPSS

Процентиль: 36%
0.00152
Низкий

8.8 High

CVSS3

Дефекты

CWE-200