CVE-2016-5006
02.05.2017, 14:59
The Cloud Controller in Cloud Foundry before 239 logs user-provided service objects at creation, which allows attackers to obtain sensitive user credential information via unspecified vectors.Enginsight
| Vendor | Product | Version |
|---|---|---|
| pivotal_software | cloud_foundry | 𝑥 ≤ 238.0 |
| pivotal_software | cloud_foundry_elastic_runtime | 𝑥 ≤ 1.6.32 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.0 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.1 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.2 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.3 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.4 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.5 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.6 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.7 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.8 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.9 |
| pivotal_software | cloud_foundry_elastic_runtime | 1.7.10 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration