Cloud Foundry Garden-runC, versions prior to 1.11.0, contains an information exposure vulnerability. A user with access to Garden logs may be able to obtain leaked credentials and perform authenticated actions using those credentials.
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
https://www.cloudfoundry.org/blog/cve-2018-1191/ | vendor advisory |