An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications errand in the PCF Elastic Runtime tile.
The product writes sensitive information to a log file.
Link | Tags |
---|---|
https://pivotal.io/security/cve-2017-4955 | mitigation vendor advisory |
http://www.securityfocus.com/bid/97082 | vdb entry third party advisory |