QID 980948
QID 980948: Java (maven) Security Update for org.springframework.credhub:spring-credhub-core (GHSA-q3jg-4c82-j4xh)
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-q3jg-4c82-j4xh for updates pertaining to this vulnerability.
Vendor References
- GHSA-q3jg-4c82-j4xh -
github.com/advisories/GHSA-q3jg-4c82-j4xh
CVEs related to QID 980948
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-q3jg-4c82-j4xh | org.springframework.credhub:spring-credhub-core |
|