Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
References
Link | Resource |
---|---|
https://www.cloudfoundry.org/blog/cve-2020-5399 | Vendor Advisory |
https://www.cloudfoundry.org/blog/cve-2020-5399 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 05:34
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cloudfoundry.org/blog/cve-2020-5399 - Vendor Advisory |
Information
Published : 2020-02-12 21:15
Updated : 2024-11-21 05:34
NVD link : CVE-2020-5399
Mitre link : CVE-2020-5399
CVE.ORG link : CVE-2020-5399
JSON object : View
Products Affected
pivotal_software
- cloud_foundry_cf-deployment
cloudfoundry
- credhub
CWE
CWE-319
Cleartext Transmission of Sensitive Information