CVE-2016-5006: Infoleak
Published May 2, 2017
·Updated
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.
Affected Software
13 affected components
Pivotal Software Cloud Foundry<=238.0
Pivotal Software Cloud Foundry Elastic Runtime<=1.6.32
Pivotal Software Cloud Foundry Elastic Runtime=1.7.0
Pivotal Software Cloud Foundry Elastic Runtime=1.7.1
Pivotal Software Cloud Foundry Elastic Runtime=1.7.2
Pivotal Software Cloud Foundry Elastic Runtime=1.7.3
Pivotal Software Cloud Foundry Elastic Runtime=1.7.4
Pivotal Software Cloud Foundry Elastic Runtime=1.7.5
Pivotal Software Cloud Foundry Elastic Runtime=1.7.6
Pivotal Software Cloud Foundry Elastic Runtime=1.7.7
Pivotal Software Cloud Foundry Elastic Runtime=1.7.8
Pivotal Software Cloud Foundry Elastic Runtime=1.7.9
Pivotal Software Cloud Foundry Elastic Runtime=1.7.10
Event History
May 2, 2017
CVE Published
via MITRE·02:00 PM
Data Sourced
via MITRE·02:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-5006?
CVE-2016-5006 is considered a moderate severity vulnerability due to the potential exposure of sensitive user credential information.
2
How do I fix CVE-2016-5006?
To fix CVE-2016-5006, you should upgrade to Cloud Foundry version 239 or later.
3
What type of vulnerability is CVE-2016-5006?
CVE-2016-5006 is an information disclosure vulnerability that affects the logging of user-provided service objects.
4
Which versions of Cloud Foundry are affected by CVE-2016-5006?
CVE-2016-5006 affects Cloud Foundry versions up to and including 238.0 and versions of Elastic Runtime up to 1.7.10.
5
What impact does CVE-2016-5006 have on security?
CVE-2016-5006 could allow attackers to access sensitive user credential information through unprotected logs.