Описание
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
Ссылки
- Vendor Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 12.2.0 (исключая)
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
Конфигурация 2Версия до 2.0.3 (исключая)
cpe:2.3:a:pivotal_software:cloud_foundry_smb_volume:*:*:*:*:*:*:*:*
EPSS
Процентиль: 64%
0.00467
Низкий
8.8 High
CVSS3
8.8 High
CVSS3
4 Medium
CVSS2
Дефекты
CWE-532
CWE-532
Связанные уязвимости
github
больше 3 лет назад
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
EPSS
Процентиль: 64%
0.00467
Низкий
8.8 High
CVSS3
8.8 High
CVSS3
4 Medium
CVSS2
Дефекты
CWE-532
CWE-532