Vulnerability Description
Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for volumes that have been recently created, allowing the user to take control of the SMB Volume.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloudfoundry | Cf-Deployment | < 12.2.0 |
| Pivotal Software | Cloud Foundry Smb Volume | < 2.0.3 |
Related Weaknesses (CWE)
References
- https://www.cloudfoundry.org/blog/cve-2019-11283Vendor Advisory
- https://www.cloudfoundry.org/blog/cve-2019-11283Vendor Advisory
FAQ
What is CVE-2019-11283?
CVE-2019-11283 is a vulnerability with a CVSS score of 8.8 (HIGH). Cloud Foundry SMB Volume, versions prior to v2.0.3, accidentally outputs sensitive information to the logs. A remote user with access to the SMB Volume logs can discover the username and password for ...
How severe is CVE-2019-11283?
CVE-2019-11283 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-11283?
Check the references section above for vendor advisories and patch information. Affected products include: Cloudfoundry Cf-Deployment, Pivotal Software Cloud Foundry Smb Volume.