CVE-2018-1223

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
17/09/2018
Last modified:
09/03/2020

Description

Cloud Foundry Container Runtime (kubo-release), versions prior to 0.14.0, may leak UAA and vCenter credentials to application logs. A malicious user with the ability to read the application logs could use these credentials to escalate privileges.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal:cloud_foundry_container_runtime:*:*:*:*:*:*:*:* 0.14.0 (excluding)


References to Advisories, Solutions, and Tools