Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.
The product inserts sensitive information into debugging code, which could expose this information if the debugging code is not disabled in production.
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
Link | Tags |
---|---|
http://www.securityfocus.com/bid/107365 | vdb entry third party advisory |
https://www.cloudfoundry.org/blog/cve-2019-3781 | vendor advisory |