CVE-2018-15763

Severity CVSS v4.0:
Pending analysis
Type:
CWE-532 Information Exposure Through Log Files
Publication date:
05/10/2018
Last modified:
09/10/2019

Description

Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credentials and perform actions using these credentials.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:pivotal_container_service:*:*:*:*:*:*:*:* 1.2 (excluding)


References to Advisories, Solutions, and Tools