Vulnerabilities > Cloud Foundry > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-10-02 CVE-2020-5422 Exposure of Resource to Wrong Sphere vulnerability in Cloud Foundry Bosh System Metrics Server
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director.
network
low complexity
cloud-foundry CWE-668
6.5
2018-12-10 CVE-2018-15800 Information Exposure vulnerability in Cloud Foundry Bits Service
Cloud Foundry Bits Service, versions prior to 2.18.0, includes an information disclosure vulnerability.
network
high complexity
cloud-foundry CWE-200
6.8