CVE-2020-5422 - CVE House
Back to Database
Status published Medium CVE-2020-5422

UAA password may appear in BOSH System Metrics Server process arguments

Vulnerability Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5422

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Cloud Foundry

View all reports →

Affected Software

BOSH System Metrics Server
Vulnerable Versions:
All

Timeline

Official Publish: October 2nd, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.