{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-04-21T18:49:59.330","vulnerabilities":[{"cve":{"id":"CVE-2021-22115","sourceIdentifier":"security@vmware.com","published":"2021-04-08T18:15:13.837","lastModified":"2024-11-21T05:49:32.233","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"Cloud Controller API versions prior to 1.106.0 logs service broker credentials if the default value of db logging config field is changed. CAPI database logs service broker password in plain text whenever a job to clean up orphaned items is run by Cloud Controller."},{"lang":"es","value":"Cloud Controller API versiones anteriores a 1.106.0, registran las credenciales del agente de servicio si el valor predeterminado del campo de configuración de registro de la base de datos es cambiado.&#xa0;La base de datos CAPI registra la contraseña del agente de servicio en texto plano cada vez que Cloud Controller ejecuta un trabajo para limpiar elementos huérfanos"}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","baseScore":6.5,"baseSeverity":"MEDIUM","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":2.8,"impactScore":3.6}],"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:P/I:N/A:N","baseScore":4.0,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":8.0,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-522"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cloudfoundry:capi-release:*:*:*:*:*:*:*:*","versionEndExcluding":"1.106.0","matchCriteriaId":"345999BB-744C-4E4F-A8A8-BF97AF611E9A"},{"vulnerable":true,"criteria":"cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*","versionEndExcluding":"16.2.0","matchCriteriaId":"9C60678F-2179-45CF-B492-7E69D4F73423"}]}]}],"references":[{"url":"https://www.cloudfoundry.org/blog/cve-2021-22115-capi-logs-service-broker-credentials/","source":"security@vmware.com","tags":["Vendor Advisory"]},{"url":"https://www.cloudfoundry.org/blog/cve-2021-22115-capi-logs-service-broker-credentials/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}