Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
References
Link | Resource |
---|---|
https://www.cloudfoundry.org/blog/cve-2020-5399 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2020-02-12 21:15
Updated : 2024-02-04 20:39
NVD link : CVE-2020-5399
Mitre link : CVE-2020-5399
CVE.ORG link : CVE-2020-5399
JSON object : View
Products Affected
cloudfoundry
- credhub
pivotal_software
- cloud_foundry_cf-deployment
CWE
CWE-319
Cleartext Transmission of Sensitive Information