Cleartext storage of sensitive information in Cloud Controller and CF Deployment - CVE-2020-5400
Published: February 25, 2020
Vulnerability details
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software logs app environment variables when an app is deployed using a server-side manifest, which may include sensitive information such as credentials if provided to the job. A remote authenticated attacker with access to those logs may gain unauthorized access to resources protected by such credentials.
Affected software
CF Deployment
How to mitigate CVE-2020-5400
CF Deployment - update to 12.33.0