Description
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2018-0767 | Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service. |
Github GHSA |
GHSA-q3jg-4c82-j4xh | Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in Pivotal CredHub Service Broker |
References
History
No history.
Status: PUBLISHED
Assigner: dell
Published:
Updated: 2024-09-16T16:47:36.058Z
Reserved: 2018-08-23T00:00:00.000Z
Link: CVE-2018-15795
No data.
Status : Modified
Published: 2018-11-13T14:29:00.340
Modified: 2024-11-21T03:51:27.953
Link: CVE-2018-15795
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA