PatchSiren

Cloudfoundry CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Cloudfoundry CVE published 2017-01-13

CVE-2016-9882

CVE-2016-9882 is a high-severity information disclosure issue in Cloud Foundry. In affected cf-release and CAPI-release versions, Cloud Controller can log credentials returned by service brokers in system component logs. Because those logs are written to disk and may also be forwarded to a log aggregator via syslog, the exposure can extend beyond the local system to any place the logs are collected or retained.