Credentials management in Cloud Foundry UAA and CF Deployment - CVE-2019-11293
Published: December 4, 2019
Vulnerability identifier: #VU23390
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11293
CWE-ID: CWE-255
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to access sensitive information on a targeted system.
The vulnerability exists due to logs client_secret credentials are sent as a query param, when set to logging level DEBUG. A remote user can gain access to user credentials via the "uaa.log" file if authentication is provided via query parameters.
Affected software
Cloud Foundry UAA
CF Deployment
CF Deployment
How to mitigate CVE-2019-11293
Install updates from vendor's website.
Cloud Foundry UAA - update to 74.10.0
CF Deployment - update to 12.12.0
CF Deployment - update to 12.12.0