CVE-2020-5422
MEDIUMBOSH System Metrics Server <0.1.0 - Info Disclosure
Title source: llmDescription
BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
Scores
CVSS v3
6.5
EPSS
0.0033
EPSS Percentile
55.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Classification
CWE
CWE-214
CWE-668
Status
published
Affected Products (1)
cloud_foundry/bosh_system_metrics_server
< 0.1.0
Timeline
Published
Oct 02, 2020
Tracked Since
Feb 18, 2026