Security Advisory

CVE-2020-5399

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2020-02-12 20:30:17
Last updated 2024-09-16 19:51:26
Assigner pivotal
CVSS score 7.6
State PUBLISHED

Description

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.