Description
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0767 | Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service. |
Github GHSA |
GHSA-q3jg-4c82-j4xh | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T16:47:36.058Z
Reserved: 2018-08-23T00:00:00.000Z
Link: CVE-2018-15795
No data.
Status : Modified
Published: 2018-11-13T14:29:00.340
Modified: 2024-11-21T03:51:27.953
Link: CVE-2018-15795
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA