Junglewise Threat Intelligence

CVE-2016-9882: Cloud Foundry Cloud Controller sensitive information disclosure in logs

CVE-2016-9882 · Severity: high · CVSS 7.5 · Published 2017-01-13

Vendors: Cloud Foundry Foundation, Cloudfoundry.

Executive brief

Cloud Foundry, a platform for managing cloud applications, was found to be recording sensitive login credentials in its system logs. These logs are stored on disk and often sent to central monitoring tools, potentially exposing passwords and access keys to unauthorized staff or anyone with access to the logging infrastructure. Organizations should update their software and rotate any credentials that may have been exposed in these logs.

Technical details

A sensitive information disclosure vulnerability (CWE-532) exists in Cloud Foundry's Cloud Controller component. The system incorrectly logs credentials returned from service brokers into system component logs. These logs are written to local disk and frequently forwarded to external log aggregators via syslog. An attacker with access to the logging infrastructure or the local filesystem could retrieve these plaintext credentials to gain unauthorized access to bound services. The issue is resolved in cf-release v250 and CAPI-release v1.12.0.

Affected products

  • Cloud Foundry Foundation cf-release prior to v250
  • Cloud Foundry Foundation CAPI-release prior to v1.12.0

Timeline

  • 2017-01-09: advisory: Initial vulnerability report published by Cloud Foundry Foundation
  • 2017-01-13: disclosed: NVD publication date

References