Description
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-26582 | VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling. |
References
| Link | Providers |
|---|---|
| https://tanzu.vmware.com/security/cve-2020-5406 |
|
History
No history.
Status: PUBLISHED
Assigner: pivotal
Published:
Updated: 2024-09-17T03:17:26.159Z
Reserved: 2020-01-03T00:00:00.000Z
Link: CVE-2020-5406
No data.
Status : Modified
Published: 2020-04-10T19:15:13.507
Modified: 2024-11-21T05:34:05.227
Link: CVE-2020-5406
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD