漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
App Autoscaler logs credentials
Vulnerability Description
VMware Tanzu Application Service for VMs (2.7.x versions prior to 2.7.19, 2.8.x versions prior to 2.8.13, and 2.9.x versions prior to 2.9.7) contains an App Autoscaler that logs the UAA admin password. This credential is redacted on VMware Tanzu Operations Manager; however, the unredacted logs are available to authenticated users of the BOSH Director. This credential would grant administrative privileges to a malicious user. The same versions of App Autoscaler also log the App Autoscaler Broker password. Prior to newer versions of Operations Manager, this credential was not redacted from logs. This credential allows a malicious user to create, delete, and modify App Autoscaler services instances. Operations Manager started redacting this credential from logs as of its versions 2.7.15, 2.8.6, and 2.9.1. Note that these logs are typically only visible to foundation administrators and operators.
CVSS Information
N/A
Vulnerability Type
信息暴露
Vulnerability Title
VMware Tanzu Operations Manager和Tanzu Application Service for VMs 日志信息泄露漏洞
Vulnerability Description
VMware Tanzu Application Service for VMs和VMware Tanzu Operations Manager都是美国威睿(VMware)公司的产品。VMware Tanzu Application Service for VMs是一套应用程序开发和部署解决方案。VMware Tanzu Operations Manager是一套Cloud Foundry自动化管理解决方案。该方案能够自动化部署、升级和管理Cloud Foundry平台。 VMware Tanzu Ope
CVSS Information
N/A
Vulnerability Type
N/A