Inclusion of Sensitive Information in Log Files in CF Deployment and Cloud Foundry UAA - CVE-2019-11290

 

Inclusion of Sensitive Information in Log Files in CF Deployment and Cloud Foundry UAA - CVE-2019-11290

Published: December 4, 2019


Vulnerability identifier: #VU23391
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-11290
CWE-ID: CWE-532
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to access sensitive information on a targeted system.

The vulnerability exists due to the affected software logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. A remote user can gain access to user credentials.


Affected software

CF Deployment
Cloud Foundry UAA

How to mitigate CVE-2019-11290

Install updates from vendor's website.

CF Deployment - update to 12.10.0
Cloud Foundry UAA - update to 74.8.0

External References

Related Security Bulletins