CVE-2020-5400
Severity CVSS v4.0:
Pending analysis
Type:
CWE-532
Information Exposure Through Log Files
Publication date:
27/02/2020
Last modified:
17/08/2021
Description
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:* | 1.91.0 (excluding) | |
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:* | 12.33.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page