Loading
Generated remediation guidance and an executive summary. No account required.
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
Use CWE-319, Cloudfoundry vendor hub and Credhub product page to widen CVE-2020-5399 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2019-3801 for nearby disclosures in the same product family.