An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.
References
Link | Resource |
---|---|
http://www.securityfocus.com/bid/97082 | Third Party Advisory VDB Entry |
https://pivotal.io/security/cve-2017-4955 | Mitigation Vendor Advisory |
http://www.securityfocus.com/bid/97082 | Third Party Advisory VDB Entry |
https://pivotal.io/security/cve-2017-4955 | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 03:26
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.securityfocus.com/bid/97082 - Third Party Advisory, VDB Entry | |
References | () https://pivotal.io/security/cve-2017-4955 - Mitigation, Vendor Advisory |
Information
Published : 2017-06-13 06:29
Updated : 2024-11-21 03:26
NVD link : CVE-2017-4955
Mitre link : CVE-2017-4955
CVE.ORG link : CVE-2017-4955
JSON object : View
Products Affected
pivotal_software
- cloud_foundry_elastic_runtime
CWE
CWE-532
Insertion of Sensitive Information into Log File