Description
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2977 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2019-11293 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T17:57:54.838Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11293
No data.
Status : Modified
Published: 2019-12-06T20:15:09.577
Modified: 2024-11-21T04:20:52.063
Link: CVE-2019-11293
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD