Inclusion of Sensitive Information in Log Files in CF Deployment and Cloud Foundry UAA - CVE-2019-11290
Published: December 4, 2019
Vulnerability details
The vulnerability allows a remote user to access sensitive information on a targeted system.
The vulnerability exists due to the affected software logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well. A remote user can gain access to user credentials.
Affected software
Cloud Foundry UAA
How to mitigate CVE-2019-11290
Cloud Foundry UAA - update to 74.8.0