Inclusion of Sensitive Information in Log Files in Cloud Foundry UAA and CF Deployment - CVE-2019-11290

 

Inclusion of Sensitive Information in Log Files in Cloud Foundry UAA and CF Deployment - CVE-2019-11290

Published: December 4, 2019


Vulnerability identifier: #VU23391
CSH Severity: Medium
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2019-11290
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: Cloud Foundry Foundation
Affected software:
Cloud Foundry UAA
CF Deployment

Detailed vulnerability description

The vulnerability allows a remote user to access sensitive information on a targeted system.

The vulnerability exists due to the affected software logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. A remote user can gain access to user credentials.


How to mitigate CVE-2019-11290

Install updates from vendor's website.

Sources