CVE-2020-5399
7.4
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.2 / Impact: 5.2
Source: NVD
Description
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
Affected (2)
Products: Cloudfoundry: Credhub · Pivotal Software: Cloud Foundry Cf Deployment
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.5.10 | |
| Before 12.29.0 |
References (2)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.