VYPR
Medium severity6.5NVD Advisory· Published Oct 2, 2020· Updated Jun 17, 2026

CVE-2020-5422

CVE-2020-5422

Description

BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • cpe:2.3:a:cloud_foundry:bosh_system_metrics_server:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:cloud_foundry:bosh_system_metrics_server:*:*:*:*:*:*:*:*range: <0.1.0
    • (no CPE)range: <0.1.0
  • Cloud Foundry/BOSH System Metrics Serverv5
    Range: All

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.