CVE-2019-11294

MEDIUM

Cloud Foundry CAPI 1.88.0 - Unauthorized Exposure of Sensitive Service Broker Information

Title source: llm
STIX 2.1

Description

Cloud Foundry Cloud Controller API (CAPI), version 1.88.0, allows space developers to list all global service brokers, including service broker URLs and GUIDs, which should only be accessible to admins.

References (1)

Core 1
Core References
Vendor Advisory x_refsource_confirm
https://www.cloudfoundry.org/blog/cve-2019-11294

Scores

CVSS v3 4.3
EPSS 0.0078
EPSS Percentile 51.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

Details

CWE
CWE-200 CWE-863
Status published
Products (2)
cloudfoundry/capi-release 1.88.0
cloudfoundry/cf-deployment < 12.7.0
Published Dec 19, 2019
Tracked Since Feb 18, 2026