CVE-2020-5422
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
02/10/2020
Last modified:
14/10/2020
Description
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
Impact
Base Score 3.x
6.50
Severity 3.x
MEDIUM
Base Score 2.0
4.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:cloud_foundry:bosh_system_metrics_server:*:*:*:*:*:*:*:* | 0.1.0 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



