Cloud Foundry Logo
blog single gear
Security Advisory

CVE-2020-5422: UAA password may appear in BOSH System Metrics Server process arguments

Severity

High

Vendor

Cloud Foundry Foundation

Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Affected Cloud Foundry Products and Versions

Severity is high unless otherwise noted.

  • BOSH System Metrics Server
    • All versions prior to 0.1.0

Mitigation

Users of affected products are strongly encouraged to follow the mitigations below. The Cloud Foundry project recommends upgrading the following releases:

  • BOSH System Metrics Server
    • Upgrade all versions to 0.1.0 or greater

History

2020-10-01: Initial vulnerability report published.

Cloud Foundry Foundation Security Team Profile Image

Cloud Foundry Foundation Security Team, AUTHOR

SEE ALL ARTICLES