The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.cloudfoundry.org/CVE-2016-5006/ | vendor advisory |
https://pivotal.io/security/cve-2016-5006 | vendor advisory |