Vulnerabilities > CVE-2020-5422 - Exposure of Resource to Wrong Sphere vulnerability in Cloud Foundry Bosh System Metrics Server

047910
CVSS 4.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
SINGLE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
cloud-foundry
CWE-668

Summary

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Vulnerable Configurations

Part Description Count
Application
Cloud_Foundry
1

Common Weakness Enumeration (CWE)