CVE-2020-5399
12.02.2020, 21:15
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.Enginsight
Vendor | Product | Version |
---|---|---|
cloudfoundry | credhub | 𝑥 < 2.5.10 |
pivotal_software | cloud_foundry_cf-deployment | 𝑥 < 12.29.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration