Sumologic operates a cloud-based data analytics and monitoring platform, with its vulnerability footprint centered on the Nozzle data-collection component and characterized by recurring issues around sensitive information exposure and insufficiently protected credentials. These weaknesses reflect the authentication and secrets-management demands of a service that ingests and processes operational data from customer environments. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Sumologic over time
Signals from CVEs in this vendor scope (1 CVEs).
1 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-3800HIGH CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local | Aug 5, 2019 | 7.8 | 26 | NO | NO |
Signals from CVEs in this vendor scope (1 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Sumologic.
Media articles that mention a CVE ID that affects a product developed by Sumologic — matched by CVE ID, not by vendor name.