#VU25574 Cleartext storage of sensitive information in CF Deployment and Cloud Controller - CVE-2020-5400
Published: February 25, 2020
CF Deployment
Cloud Controller
Cloud Foundry Foundation
Description
The vulnerability allows a remote attacker to gain access to potentially sensitive information.
The vulnerability exists due to the affected software logs app environment variables when an app is deployed using a server-side manifest, which may include sensitive information such as credentials if provided to the job. A remote authenticated attacker with access to those logs may gain unauthorized access to resources protected by such credentials.