Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.
2019-03-07T18:29:00.587
2024-11-21T04:42:31.827
Modified
CVSSv3.1: 8.8 (HIGH)
AV:N/AC:M/Au:S/C:P/I:N/A:N
6.8
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | cloudfoundry | command_line_interface | < 6.43.0 | Yes |