CVE-2018-15795: Pivotal Software Credhub Service Broker

High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.

Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.

Affected products

Published 2018-11-13. Last modified 2026-06-17.