First published: Thu Mar 29 2018(Updated: )
MySQL for PCF tiles 1.7.x before 1.7.10 were discovered to log the AWS access key in plaintext. These credentials were logged to the Service Backup component logs, and not the system log, thus were not exposed outside the Service Backup VM.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Vmware Pivotal Software Mysql | =1.7.0 | |
Vmware Pivotal Software Mysql | =1.7.0.1 | |
Vmware Pivotal Software Mysql | =1.7.0.2 | |
Vmware Pivotal Software Mysql | =1.7.0.3 | |
Vmware Pivotal Software Mysql | =1.7.0.4 | |
Vmware Pivotal Software Mysql | =1.7.1 | |
Vmware Pivotal Software Mysql | =1.7.2 | |
Vmware Pivotal Software Mysql | =1.7.3 | |
Vmware Pivotal Software Mysql | =1.7.4 | |
Vmware Pivotal Software Mysql | =1.7.5 | |
Vmware Pivotal Software Mysql | =1.7.6 | |
Vmware Pivotal Software Mysql | =1.7.7 | |
Vmware Pivotal Software Mysql | =1.7.8 | |
Vmware Pivotal Software Mysql | =1.7.9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0898 has a severity level classified as medium due to the exposure of AWS access keys in plaintext.
CVE-2016-0898 specifically affects versions of MySQL for PCF tiles from 1.7.0 to 1.7.9, where AWS access keys are logged in plaintext.
To fix CVE-2016-0898, upgrade your MySQL for PCF installation to version 1.7.10 or later.
Versions 1.7.0 through 1.7.9 of MySQL for PCF are vulnerable to CVE-2016-0898.
While CVE-2016-0898 logs AWS access keys in plaintext, they are only exposed within the Service Backup component logs, not outside the VM.