Vulnerability Description
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cloud Foundry | Bosh System Metrics Server | < 0.1.0 |
Related Weaknesses (CWE)
References
- https://www.cloudfoundry.org/blog/cve-2020-5422Vendor Advisory
- https://www.cloudfoundry.org/blog/cve-2020-5422Vendor Advisory
FAQ
What is CVE-2020-5422?
CVE-2020-5422 is a vulnerability with a CVSS score of 6.5 (MEDIUM). BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same ...
How severe is CVE-2020-5422?
CVE-2020-5422 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5422?
Check the references section above for vendor advisories and patch information. Affected products include: Cloud Foundry Bosh System Metrics Server.