Home Embedded Vulns General Vulns

CVE-2020-5399

HIGH 7.4

Our Analysis: General Purpose

Our model has classified this vulnerability as relevant to General Purpose Systems, helping your team prioritize efforts effectively.

Published Date February 12, 2020
Last Modified November 21, 2024
CVSS Vector Not Available

Description

Cloud Foundry CredHub, versions prior to 2.5.10, connects to a MySQL database without TLS even when configured to use TLS. A malicious user with access to the network between CredHub and its MySQL database may eavesdrop on database connections and thereby gain unauthorized access to CredHub and other components.

Potentially Affected Vendors