CVE-2025-22246

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*

History

11 Jul 2025, 15:50

Type Values Removed Values Added
References () https://www.cloudfoundry.org/blog/cve-2025-22246-uaa-private-key-exposure/ - () https://www.cloudfoundry.org/blog/cve-2025-22246-uaa-private-key-exposure/ - Vendor Advisory, Mitigation
First Time Cloudfoundry uaa Release
Cloudfoundry cf-deployment
Cloudfoundry
CPE cpe:2.3:a:cloudfoundry:uaa_release:*:*:*:*:*:*:*:*
cpe:2.3:a:cloudfoundry:cf-deployment:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

13 May 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-13 06:15

Updated : 2025-07-11 15:50


NVD link : CVE-2025-22246

Mitre link : CVE-2025-22246


JSON object : View

Products Affected

cloudfoundry

  • cf-deployment
  • uaa_release
CWE

No CWE.