First published: Mon Nov 25 2019(Updated: )
Cloud Foundry UAA Release, versions prior to v74.8.0, logs all query parameters to tomcat’s access file. If the query parameters are used to provide authentication, ie. credentials, then they will be logged as well.
Credit: security@pivotal.io
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudfoundry Cf-deployment | <12.10.0 | |
Cloudfoundry User Account And Authentication | <74.8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11290 is a vulnerability in Cloud Foundry UAA Release versions prior to v74.8.0 that logs all query parameters, including credentials, to tomcat’s access file.
CVE-2019-11290 affects Cloud Foundry UAA Release versions prior to v74.8.0 by logging all query parameters, including credentials, to tomcat’s access file.
CVE-2019-11290 has a severity rating of 7.5 (High).
To fix CVE-2019-11290, upgrade to Cloud Foundry UAA Release version v74.8.0 or higher.
CVE-2019-11290 is associated with CWE-532 (Information Exposure Through Log Files).