Vulnerabilities (CVE)

Filtered by vendor Cloud Foundry Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-5422 1 Cloud Foundry 1 Bosh System Metrics Server 2020-10-14 4.0 MEDIUM 6.5 MEDIUM
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
CVE-2018-15800 1 Cloud Foundry 1 Bits Service 2019-10-09 3.5 LOW 6.8 MEDIUM
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability. A remote malicious user may execute a timing attack to brute-force the signing key, allowing them complete read and write access to the the Bits Service storage.