CVE-2025-22246

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*

History

11 Jul 2025, 15:50

Type Values Removed Values Added
References () https://www.cloudfoundry.org/blog/cve-2025-22246-uaa-private-key-exposure/ - () https://www.cloudfoundry.org/blog/cve-2025-22246-uaa-private-key-exposure/ - Vendor Advisory, Mitigation
CPE cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*
First Time Cloudfoundry cf-deployment
Cloudfoundry
Cloudfoundry uaa Release

13 May 2025, 14:15

Type Values Removed Values Added
CWE CWE-532
Summary
  • (es) Las versiones de lanzamiento de Cloud Foundry UAA de v77.21.0 a v7.31.0 son vulnerables a una exposición de clave privada en los registros.

13 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 06:15

Updated : 2025-07-11 15:50


NVD link : CVE-2025-22246

Mitre link : CVE-2025-22246

CVE.ORG link : CVE-2025-22246


JSON object : View

Products Affected

cloudfoundry

  • uaa_release
  • cf-deployment
CWE
CWE-532

Insertion of Sensitive Information into Log File