Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown
PKS Telemetry logs credentials
Disclosure Date: July 23, 2019 (last updated November 27, 2024)
Pivotal Container Services (PKS) versions 1.3.x prior to 1.3.7, and versions 1.4.x prior to 1.4.1, contains a vulnerable component which logs the username and password to the billing database. A remote authenticated user with access to those logs may be able to retrieve non-sensitive information.
0
Attacker Value
Unknown
PKS leaks IaaS Credentials to Application Logs
Disclosure Date: October 05, 2018 (last updated November 27, 2024)
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application logs may be able to obtain IaaS credentials and perform actions using these credentials.
0