Loading
Generated remediation guidance and an executive summary. No account required.
Cloud Foundry NFS volume release, 1.2.x prior to 1.2.5, 1.5.x prior to 1.5.4, 1.7.x prior to 1.7.3, logs the cf admin username and password when running the nfsbrokerpush BOSH deploy errand. A remote authenticated user with access to BOSH can obtain the admin credentials for the Cloud Foundry Platform through the logs of the NFS volume deploy errand.
Use CWE-532, Pivotal Software vendor hub and Cloud Foundry Nfs Volume product page to widen CVE-2018-15797 into its surrounding weakness, vendor, and product context.