Inclusion of Sensitive Information in Log Files in Cloud Foundry UAA and CF Deployment - CVE-2019-11290
Published: December 4, 2019
Cloud Foundry UAA
CF Deployment
Detailed vulnerability description
The vulnerability allows a remote user to access sensitive information on a targeted system.
The vulnerability exists due to the affected software logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. A remote user can gain access to user credentials.