Re: CVE-2016-9882: Cloud Foundry Logs Service Credentials
Nicholas Calugar
Hi Mike,
toggle quoted message
Show quoted text
That’s a valid point. We [1] changed the default log level from debug2 to info in CF-239, however, we think a lot of production Cloud Foundry deployments may still use verbose logging levels. [1] https://github.com/cloudfoundry/cloud_controller_ng/commit/46d882888d45a3b8ce8e0766e5f85b7abe2673d2 Nick -- Nicholas Calugar On January 9, 2017 at 4:13:31 PM, Mike Youngstrom (youngm(a)gmail.com) wrote:
It appears this only applies if you have debug enabled on the cloud controller. Correct? https://github.com/cloudfoundry/cloud_controller_ng/commit/21b9db9d1a58b9154f65404b34bf2e9e4c6260ae On Mon, Jan 9, 2017 at 11:28 AM, Molly Crowther <mcrowther(a)cloudfoundry.org> wrote: The following CVE has been announced on cloudfoundry.org/security. |
|