CVE-2020-5426 - CVE House
Back to Database
Status published High CVE-2020-5426

Scheduler for TAS can transmit privileged UAA token in plaintext

Vulnerability Description

Scheduler for TAS prior to version 1.4.0 was permitting plaintext transmission of UAA client token by sending it over a non-TLS connection. This also depended on the configuration of the MySQL server which is used to cache a UAA client token used by the service. If intercepted the token can give an attacker admin level access in the cloud controller.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-5426

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

VMware Tanzu

View all reports →

Affected Software

Pivotal Scheduler
Vulnerable Versions:
All

Timeline

Official Publish: November 11th, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:L

Weaknesses (CWE)