Description
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2960 | Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2019-11271 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T00:37:19.176Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11271
No data.
Status : Modified
Published: 2019-06-19T00:15:12.593
Modified: 2024-11-21T04:20:49.597
Link: CVE-2019-11271
No data.
OpenCVE Enrichment
No data.
EUVD