SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-5399

A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.

HIGH 7.4EPSS 0.53%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (0.53%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.

CVSS 3.1
7.4 HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS
0.53% probability · 43th percentile
CISA KEV
Not listed
Weakness
CWE-319
Affected
cloudfoundry/credhub · pivotal software/cloud foundry cf-deployment
Source
security@pivotal.io

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.