CVE-2020-5399
Published Feb 12, 2020Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between Cred…
Vendor/product archive
2 CVEs tagged to cloudfoundry / credhub — 1 Critical, 1 High, 0 Medium, 0 Low, 0 Unrated.
Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between Cred…
Cloud Foundry cf-deployment, versions prior to 7.9.0, contain java components that are using an insecure protocol to fetch dependencies when building. A remote unauthenticated mal…