CVE-2016-0929

CVE-2016-0929

The metrics-collection component in RabbitMQ for Pivotal Cloud Foundry (PCF) 1.6.x before 1.6.4 logs command lines of failed commands, which might allow context-dependent attackers to obtain sensitive information by reading the log data, as demonstrated by a syslog message that contains credentials from a command line.

Source: CVE-2016-0929

CVE-2016-0926 (cloud_foundry_elastic_runtime)

CVE-2016-0926 (cloud_foundry_elastic_runtime)

Cross-site scripting (XSS) vulnerability in Apps Manager in Pivotal Cloud Foundry (PCF) Elastic Runtime before 1.6.32 and 1.7.x before 1.7.8 allows remote attackers to inject arbitrary web script or HTML via unspecified input that improperly interacts with the AngularJS framework.

Source: CVE-2016-0926 (cloud_foundry_elastic_runtime)