VYPR
High severityNVD Advisory· Published Nov 13, 2018· Updated Sep 16, 2024

CredHub Service Broker uses guessable client secret

CVE-2018-15795

Description

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
org.springframework.credhub:spring-credhub-coreMaven
< 1.1.01.1.0

Affected products

1

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

4

News mentions

0

No linked articles in our index yet.