CVE-2018-15795 describes a critical vulnerability in Pivotal CredHub Service Broker versions prior to 1.1.0, where a guessable random number generation method was used for UAA client secrets. This flaw allows a remote attacker to potentially guess the client secret, leading to unauthorized access or modification of user credentials within the CredHub Service. With a CVSS score of 8.1 (HIGH), this vulnerability presents a low attack complexity and high impact on confidentiality and integrity, despite requiring low privileges. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.1.0CPE matchmatch criteria | cpe:2.3:a:pivotal_software:credhub_service_broker:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.