Lucene search

K
cloudfoundryCloud FoundryCFOUNDRY:F2395754936DF3DD6FB4BC25F43B2C1E
HistoryOct 01, 2020 - 12:00 a.m.

CVE-2020-5422: UAA password may appear in BOSH System Metrics Server process arguments | Cloud Foundry

2020-10-0100:00:00
Cloud Foundry
www.cloudfoundry.org
12

0.001 Low

EPSS

Percentile

28.4%

Severity

High

Vendor

Cloud Foundry Foundation

Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Affected Cloud Foundry Products and Versions

Severity is high unless otherwise noted.

  • BOSH System Metrics Server
    • All versions prior to 0.1.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • BOSH System Metrics Server
    • Upgrade all versions to 0.1.0 or greater

History

2020-10-01: Initial vulnerability report published.

CPENameOperatorVersion
bosh system metrics serverlt0.1.0

0.001 Low

EPSS

Percentile

28.4%

Related for CFOUNDRY:F2395754936DF3DD6FB4BC25F43B2C1E