← back
CVE-2020-5406

PCF Autoscaling logs its database credentials

EPSS 1.0%CWE-522
VMware Tanzu Application Service for VMs, 2.6.x versions prior to 2.6.18, 2.7.x versions prior to 2.7.11, and 2.8.x versions prior to 2.8.5, includes a version of PCF Autoscaling that writes database connection properties to its log, including database username and password. A malicious user with access to those logs may gain unauthorized access to the database being used by Autoscaling.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →