CVE-2019-11293: UAA logs all query parameters with debug logging level
Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs clientsecret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11293?
CVE-2019-11293 is a vulnerability found in Cloud Foundry UAA Release versions prior to v74.10.0.
What is the severity of CVE-2019-11293?
CVE-2019-11293 has a severity rating of 6.5 (high).
How does CVE-2019-11293 affect Cloudfoundry Cf-deployment?
Cloudfoundry Cf-deployment versions up to 12.12.0 are affected by CVE-2019-11293.
How does CVE-2019-11293 affect Cloudfoundry User Account And Authentication?
Cloudfoundry User Account And Authentication versions up to 74.10.0 are affected by CVE-2019-11293.
How can a remote authenticated malicious user exploit CVE-2019-11293?
A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.