CVE-2018-15795

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
13/11/2018
Last modified:
09/10/2019

Description

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:pivotal_software:credhub_service_broker:*:*:*:*:*:*:*:* 1.1.0 (excluding)