CVE-2025-22246

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs. (CVE-2025-22246)

Description

Cloud Foundry UAA release versions from v77.21.0 to v7.31.0 are vulnerable to a private key exposure in logs.

Metrics

Severity
low
no public PoC known
3.0
Source: nvd-v3
9.4 %
Low — this CVE sits in the lower 10% of all CVEs scored today.
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2025-05-13 05:14 UTC

Affected products

Products and version ranges extracted from the vendor/CERT advisory. A range like „<4.14.6“ implies the update recommendation „upgrade to 4.14.6 or later“.

  • cloudfoundry

    cf-deployment45.1.0 – 49.0.0

  • cloudfoundry

    uaa_release77.21.0 – 77.32.0

References & sources

IDCVE-2025-22246