CVE-2019-11271

Source
https://cve.org/CVERecord?id=CVE-2019-11271
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11271.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2019-11271
Published
2019-06-19T00:15:12.593Z
Modified
2025-11-14T09:04:30.604620Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Cloud Foundry BOSH 270.x versions prior to v270.1.1, contain a BOSH Director that does not properly redact credentials when configured to use a MySQL database. A local authenticated malicious user may read any credentials that are contained in a BOSH manifest.

References

Affected packages

Git / github.com/cloudfoundry/bosh

Affected ranges

Type
GIT
Repo
https://github.com/cloudfoundry/bosh
Events

Affected versions

v270.*

v270.0.0
v270.1.0

Database specific

source

"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2019-11271.json"