First published: Mon Sep 17 2018(Updated: )
Pivotal Cloud Cache, versions prior to 1.3.1, prints a superuser password in plain text during BOSH deployment logs. A malicious user with access to the logs could escalate their privileges using this password.
Credit: security_alert@emc.com
Affected Software | Affected Version | How to fix |
---|---|---|
Pivotal Software Pivotal Cloud Cache | <1.3.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1198 is a vulnerability in Pivotal Cloud Cache that allows a malicious user to escalate their privileges by accessing a superuser password in plain text.
CVE-2018-1198 has a severity score of 8.8 out of 10, indicating a high severity vulnerability.
A malicious user can exploit CVE-2018-1198 by accessing the BOSH deployment logs where the superuser password is printed in plain text.
Versions of Pivotal Cloud Cache prior to 1.3.1 are affected by CVE-2018-1198.
To fix CVE-2018-1198, upgrade to Pivotal Cloud Cache version 1.3.1 or later.