CVE-2018-1264

CRITICAL
9.1CVSS
Published: 2018-10-05
Updated: 2024-11-21
AI Analysis

Description

Cloud Foundry Log Cache, versions prior to 1.1.1, logs its UAA client secret on startup as part of its envstruct report. A remote attacker who has gained access to the Log Cache VM can read this secret, gaining all privileges held by the Log Cache UAA client. In the worst case, if this client is an admin, the attacker would gain complete control over the Foundation.

CVSS Metrics

Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Attack Vector
network
Complexity
low
Privileges
high
User Action
none
Scope
changed
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-532

Metadata

Primary Vendor
PIVOTAL_SOFTWARE
Published
10/5/2018
Last Modified
11/21/2024
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

pivotal_software : cloud_foundry_log_cache

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief