CVE-2019-3800
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Affected (60)
Products: Pivotal: Cloud Foundry Command Line Interface, Cloud Foundry Command Line Interface Release, Cloud Foundry Deployment, Cloud Foundry Deployment Concourse Tasks, Cloud Foundry Log Cache Release, Cloud Foundry Networking Release, Cloud Foundry Notifications, Cloud Foundry Routing Release, Cloud Foundry Smoke Test, Application Service, Cloud Foundry Autoscaling Release, Cloud Foundry Event Alerts, Cloud Foundry Healthwatch, Credhub Service Broker For Pcf, Metric Registrar Release, On Demand Service Broker, Pivotal Cloud Foundry Service Broker, Single Sign On · Anynines: Elasticsearch, Logme, Mongodb, Mysql, Postgresql, Rabbitmq, Redis · Apigee: Edge Service Broker · +24 more
Show all products
Pivotal: Cloud Foundry Command Line Interface, Cloud Foundry Command Line Interface Release, Cloud Foundry Deployment, Cloud Foundry Deployment Concourse Tasks, Cloud Foundry Log Cache Release, Cloud Foundry Networking Release, Cloud Foundry Notifications, Cloud Foundry Routing Release, Cloud Foundry Smoke Test, Application Service, Cloud Foundry Autoscaling Release, Cloud Foundry Event Alerts, Cloud Foundry Healthwatch, Credhub Service Broker For Pcf, Metric Registrar Release, On Demand Service Broker, Pivotal Cloud Foundry Service Broker, Single Sign On · Anynines: Elasticsearch, Logme, Mongodb, Mysql, Postgresql, Rabbitmq, Redis · Apigee: Edge Service Broker · Appdynamics: Application Analytics, Application Performance Monitoring, Platform Montioring · Bluemedora: Nozzle · Contrastsecurity: Service Broker · Cyberark: Conjur Service Broker · Datadoghq: Application Monitoring · Datastax: Enterprise Service Broker · Dynatrace: Service Broker · Forgerock: Service Broker · Google: Google Cloud Platform Service Broker · Ibm: Websphere Liberty · Microsoft: Azure Log Analytics Nozzle, Azure Service Broker · Newrelic: Dotnet Extension Buildpack, Nozzle, Service Broker · Pagerduty: Service Broker · Riverbed: Steelcentral Appinternals · Samba: Volume Service · Signalsciences: Service Broker · Snyk: Service Broker · Solace: Pubsub+ · Splunk: Nozzle · Sumologic: Nozzle · Synopsys: Seeker Iast Service Broker · Tibco: Businessworks Buildpack · Wavefront: Wavefront By Vmware Nozzle · Yugabyte: Db Enterprise
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 6.45.0 | |
| Before 1.16.0 | |
| Before 10.0.0 | |
| Before 9.3.0 | |
| Before 2.3.1 | |
| Before 2.23.0 | |
| Before 58 | |
| Before 0.189.0 | |
| Before 40.0.113 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.3.0 to 2.3.14 | |
| Before 219 | |
| Before 1.2.8 | |
| From 1.4.0 to 1.4.7 | |
| Before 1.3.2 | |
| Before 1.2 | |
| Before 0.29.0 | |
| Before 1.4.13 | |
| From 1.7.0 to 1.7.5 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 2.1.2 | |
| Before 3.1.3 | |
| Before 4.7.652 | |
| Before 4.6.64 | |
| Before 4.7.712 | |
| Before 3.1.1 | |
| Before 2.2.0 | |
| Before 1.1.1 | |
| Before 1.7.0 | |
| Before 1.0.2 | |
| Before 1.4.2 | |
| Before 2.1.2 | |
| Before 4.2.3 | |
| Before 3.11.0 | |
| Before 1.4.1 | |
| Before 1.4.1 | |
| Before 1.1.1 | |
| Before 1.1.17 | |
| Before 1.12.64 | |
| Before 1.2.4 | |
| Before 10.21.1-bl516 | |
| Before 1.1.1 | |
| Before 1.1.0 | |
| Before 1.0.3 | |
| Before 2.3.2 | |
| Before 1.1.1 | |
| Before 1.0.1 | |
| Before 1.2.14 | |
| Before 2.4.4 | |
| Before 1.0.2 | |
| Before 1.1.8 |
Related CWEs
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-522
Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
References (4)
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.