CVE-2025-22246

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
13/05/2025
Last modified:
11/07/2025

Description

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* 45.1.0 (including) 49.0.0 (excluding)
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:* 77.21.0 (including) 77.32.0 (excluding)