CVE-2019-11271: Bosh Deployment logs leak sensitive information
Published Jun 18, 2019
·Updated
Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.
Affected Software
1 affected component
Cloud Foundry Bosh>=270.0.0<270.1.1
Event History
Jun 18, 2019
CVE Published
via MITRE·11:38 PM
Data Sourced
via MITRE·11:38 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-11271?
CVE-2019-11271 is considered a high severity vulnerability due to its potential for credential exposure.
2
How do I fix CVE-2019-11271?
To fix CVE-2019-11271, upgrade the Cloud Foundry BOSH to version 270.1.1 or later.
3
What impact does CVE-2019-11271 have on my system?
CVE-2019-11271 allows local authenticated malicious users to read unredacted credentials in BOSH manifests.
4
Which versions of Cloud Foundry BOSH are affected by CVE-2019-11271?
CVE-2019-11271 affects Cloud Foundry BOSH versions 270.0.0 and earlier.
5
Is CVE-2019-11271 a remote exploit?
No, CVE-2019-11271 requires local authentication for exploitation.