Description
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-2977 | Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters. |
References
| Link | Providers |
|---|---|
| https://www.cloudfoundry.org/blog/cve-2019-11293 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-16T17:57:54.838Z
Reserved: 2019-04-18T00:00:00.000Z
Link: CVE-2019-11293
No data.
Status : Modified
Published: 2019-12-06T20:15:09.577
Modified: 2024-11-21T04:20:52.063
Link: CVE-2019-11293
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD