CVE-2018-1198

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
17/09/2018
Last modified:
21/11/2018

Description

Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:pivotal_cloud_cache:*:*:*:*:*:*:*:* 1.3.1 (excluding)


References to Advisories, Solutions, and Tools