Cloud Foundry Credhub 1.9.8

CPE Details

Cloud Foundry Credhub 1.9.8
1.9.8
2019-04-26
16h09 +00:00
2021-03-24
15h27 +00:00
Alerte pour un CPE
Stay informed of any changes for a specific CPE.
Notifications manage

CPE Name: cpe:2.3:a:cloudfoundry:credhub:1.9.8:*:*:*:*:*:*:*

Informations

Vendor

cloudfoundry

Product

credhub

Version

1.9.8

Related CVE

Open and find in CVE List

CVE ID Published Description Score Severity
CVE-2020-5399 2020-02-12 20h30 +00:00 Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.
7.4
High
CVE-2019-3801 2019-04-25 20h17 +00:00 Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated malicious attacker could hijack the DNS entry for the dependency, and inject malicious code into the component.
9.8
Critical