CVE-2022-22939
published 2022-02-04CVE-2022-22939: VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC…
PriorityP425medium4.9CVSS 3.1
AVNACLPRHUINSUCHINAN
EPSS
0.78%
52.1th percentile
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| vmware | cloud_foundation | 3.0 – 3.10.2.2 | — |
| vmware | cloud_foundation | 4.0 – 4.1.0.1 | — |
CVSS provenance
nvdv3.14.9MEDIUMCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.0MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VMware
VMware Cloud Foundation contains an information disclosure vulnerability due to the logging of plaintext credentials within some log files.
vendor_vmware·2022-01-31·CVSS 4.9
CVE-2022-22939 [MEDIUM] VMware Cloud Foundation contains an information disclosure vulnerability due to the logging of plaintext credentials within some log files.
VMSA-2022-0003: VMware Cloud Foundation contains an information disclosure vulnerability due to the logging of plaintext credentials within some log files.
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager.
CVEs: CVE-2022-22939
Affected products: VMware Cloud Foundation
GHSA
GHSA-95v7-jv4x-23ww: VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the
ghsa_unreviewed·2022-02-11
CVE-2022-22939 [MEDIUM] CWE-532 GHSA-95v7-jv4x-23ww: VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the
VMware Cloud Foundation contains an information disclosure vulnerability due to logging of credentials in plain-text within multiple log files on the SDDC Manager. A malicious actor with root access on VMware Cloud Foundation SDDC Manager may be able to view credentials in plaintext within one or more log files.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-02-04
Published