CVE-2019-11293: Cloudfoundry Cf-Deployment

Medium severity, CVSS 6.5. EPSS: 1.3% chance of exploitation in the next 30 days.

Cloud Foundry UAA Release, versions prior to v74.10.0, when set to logging level DEBUG, logs client_secret credentials when sent as a query parameter. A remote authenticated malicious user could gain access to user credentials via the uaa.log file if authentication is provided via query parameters.

Affected products

  • Cloudfoundry Cf-Deployment: before 12.12.0 (fixed in 12.12.0)
  • Cloudfoundry User Account And Authentication: before 74.10.0 (fixed in 74.10.0)

Published 2019-12-06. Last modified 2026-06-17.