CVE-2019-11283
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD
Description
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
Affected (2)
Products: Cloudfoundry: Cf Deployment · Pivotal Software: Cloud Foundry Smb Volume
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 12.2.0 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.0.3 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.