HIGH · 8.8

CVE-2019-11283

Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for ...

Vulnerability Description

Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.

CVSS Score

8.8

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
CloudfoundryCf-Deployment< 12.2.0
Pivotal SoftwareCloud Foundry Smb Volume< 2.0.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-11283?

CVE-2019-11283 is a vulnerability with a CVSS score of 8.8 (HIGH). Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for ...

How severe is CVE-2019-11283?

CVE-2019-11283 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-11283?

Check the references section above for vendor advisories and patch information. Affected products include: Cloudfoundry Cf-Deployment, Pivotal Software Cloud Foundry Smb Volume.