2.1
CVSSv2

CVE-2019-3800

Published: 05/08/2019 Updated: 09/10/2019
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

pivotal cloud foundry notifications

pivotal cloud foundry log cache release

pivotal cloud foundry deployment concourse tasks

pivotal cloud foundry deployment

pivotal cloud foundry smoke test

pivotal cloud foundry routing release

pivotal cloud foundry networking release

pivotal cloud foundry command line interface release

pivotal cloud foundry command line interface

pivotal pivotal cloud foundry service broker

pivotal on demand service broker

pivotal metric registrar release

pivotal credhub service broker for pcf

pivotal cloud foundry autoscaling release

pivotal cloud foundry event alerts

pivotal application service

pivotal cloud foundry healthwatch

pivotal single sign-on

apigee edge service broker

newrelic dotnet extension buildpack

microsoft azure service broker

appdynamics application analytics

appdynamics application performance monitoring

appdynamics platform montioring

bluemedora nozzle

contrastsecurity service broker

cyberark conjur service broker

datadoghq application monitoring

datastax enterprise service broker

dynatrace service broker

forgerock service broker

google google cloud platform service broker

ibm websphere liberty

microsoft azure log analytics nozzle

newrelic nozzle

newrelic service broker

pagerduty service broker

riverbed steelcentral appinternals

signalsciences service broker

wavefront wavefront by vmware nozzle

tibco businessworks buildpack

solace pubsub+

snyk service broker

samba volume service

splunk nozzle

sumologic nozzle

synopsys seeker iast service broker

yugabyte db enterprise

anynines elasticsearch

anynines logme

anynines mysql

anynines postgresql

anynines rabbitmq

anynines redis

anynines mongodb