CVE-2018-15795: Pivotal Software Credhub Service Broker
High severity, CVSS 8.1. EPSS: 1.3% chance of exploitation in the next 30 days.
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Affected products
- Pivotal Software Credhub Service Broker: before 1.1.0 (fixed in 1.1.0)
Published 2018-11-13. Last modified 2026-06-17.