CVE-2020-5422

MEDIUM

BOSH System Metrics Server <0.1.0 - Info Disclosure

Title source: llm

Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Scores

CVSS v3 6.5
EPSS 0.0033
EPSS Percentile 55.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-214 CWE-668
Status published

Affected Products (1)

cloud_foundry/bosh_system_metrics_server < 0.1.0

Timeline

Published Oct 02, 2020
Tracked Since Feb 18, 2026