Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credentials and perform actions using these credentials.
2018-10-05T21:29:01.107
2024-11-21T03:51:25.417
Modified
CVSSv3.0: 9.0 (CRITICAL)
AV:N/AC:L/Au:S/C:P/I:N/A:N
8.0
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | pivotal_software | pivotal_container_service | < 1.2 | Yes |