← back
CVE-2020-5400highCWE-522

Cloud Controller logs environment variables from app manifests

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8epss 0.8%
exploitation probability
0.8%top 49% of all CVEs
observed exploitation
nono source reports it
Cloud Foundry Cloud Controller (CAPI), versions prior to 1.91.0, logs properties of background jobs when they are run, which may include sensitive information such as credentials if provided to the job. A malicious user with access to those logs may gain unauthorized access to resources protected by such credentials.
CVSS:3.0/AV:N/AC:H/PR:L/UI:R/S:C/C:H/I:H/A:H
Affected products
Cloud Foundry · CAPI