Security Advisory

CVE-2018-15797

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2018-12-05 18:00:00
Last updated 2024-09-16 18:24:31
Assigner dell
State PUBLISHED

Description

Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH can obtain the admin credentials for the Cloud Foundry Platform through the logs of the NFS volume deploy errand.