BOSH System Metrics Server releases prior to 0.1.0 exposed the UAA password as a flag to a process running on the BOSH director. It exposed the password to any user or process with access to the same VM (through ps or looking at process details).
References
Link Resource
https://www.cloudfoundry.org/blog/cve-2020-5422 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: pivotal

Published: 2020-10-01T00:00:00

Updated: 2020-10-02T17:10:12

Reserved: 2020-01-03T00:00:00


Link: CVE-2020-5422

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2020-10-02T17:15:12.537

Modified: 2020-10-14T14:16:39.580


Link: CVE-2020-5422

JSON object: View

cve-icon Redhat Information

No data.