← back
CVE-2019-11290highCWE-532

Cloud Foundry UAA logs query parameters in tomcat access file

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 1.3%
exploitation probability
1.3%top 33% of all CVEs
observed exploitation
nono source reports it
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H