Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
References
Link | Resource |
---|---|
https://www.cloudfoundry.org/blog/cve-2020-5399 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
Information
Published : 2020-02-12 13:15
Updated : 2020-02-27 08:45
NVD link : CVE-2020-5399
Mitre link : CVE-2020-5399
JSON object : View
CWE
CWE-319
Cleartext Transmission of Sensitive Information
Products Affected
pivotal_software
- cloud_foundry_cf-deployment
cloudfoundry
- credhub