7.8
CVE-2019-3800
- EPSS 2.09%
- Veröffentlicht 05.08.2019 17:15:10
- Zuletzt bearbeitet 21.11.2024 04:42:33
- Erkennungen
CF CLI writes the client id and secret to config file
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal ≫ Cloud Foundry Command Line Interface Version < 6.45.0
Pivotal ≫ Cloud Foundry Command Line Interface Release Version < 1.16.0
Pivotal ≫ Cloud Foundry Deployment Version < 10.0.0
Pivotal ≫ Cloud Foundry Deployment Concourse Tasks Version < 9.3.0
Pivotal ≫ Cloud Foundry Log Cache Release Version < 2.3.1
Pivotal ≫ Cloud Foundry Networking Release Version < 2.23.0
Pivotal ≫ Cloud Foundry Notifications Version < 58
Pivotal ≫ Cloud Foundry Routing Release Version < 0.189.0
Pivotal ≫ Cloud Foundry Smoke Test Version < 40.0.113
Pivotal ≫ Application Service Version >= 2.3.0 < 2.3.14
Pivotal ≫ Application Service Version >= 2.4.0 < 2.4.10
Pivotal ≫ Application Service Version >= 2.5.0 < 2.5.6
Pivotal ≫ Cloud Foundry Autoscaling Release Version < 219
Pivotal ≫ Cloud Foundry Event Alerts Version < 1.2.8
Pivotal ≫ Cloud Foundry Healthwatch Version >= 1.4.0 < 1.4.7
Pivotal ≫ Cloud Foundry Healthwatch Version >= 1.5.0 < 1.5.4
Pivotal ≫ Credhub Service Broker For Pcf Version < 1.3.2
Pivotal ≫ Metric Registrar Release Version < 1.2
Pivotal ≫ On Demand Service Broker Version < 0.29.0
Pivotal ≫ Pivotal Cloud Foundry Service Broker SwPlatform aws Version < 1.4.13
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.7.0 < 1.7.5
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.8.0 < 1.8.4
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.9.0 < 1.9.1
Anynines ≫ Elasticsearch SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Postgresql SwPlatform pivotal_cloud_foundry Version < 2.1.2
Apigee ≫ Edge Service Broker SwPlatform pivotal_cloud_foundry Version < 3.1.3
Appdynamics ≫ Application Analytics SwPlatform pivotal_cloud_foundry Version < 4.7.652
Appdynamics ≫ Application Performance Monitoring SwPlatform pivotal_cloud_foundry Version < 4.6.64
Appdynamics ≫ Platform Montioring SwPlatform pivotal_cloud_foundry Version < 4.7.712
Bluemedora ≫ Nozzle SwPlatform pivotal_cloud_foundry Version < 3.1.1
Contrastsecurity ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 2.2.0
Cyberark ≫ Conjur Service Broker SwPlatform pivotal_cloud_foundry Version < 1.1.1
Datadoghq ≫ Application Monitoring SwPlatform pivotal_cloud_foundry Version < 1.7.0
Datastax ≫ Enterprise Service Broker SwPlatform pivotal_cloud_foundry Version < 1.0.2
Dynatrace ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.4.2
Forgerock ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 2.1.2
Google ≫ Google Cloud Platform Service Broker SwPlatform pivotal_cloud_foundry Version < 4.2.3
Ibm ≫ Websphere Liberty SwPlatform pivotal_cloud_foundry Version < 3.11.0
Microsoft ≫ Azure Log Analytics Nozzle SwPlatform pivotal_cloud_foundry Version < 1.4.1
Microsoft ≫ Azure Service Broker SwPlatform pivotal_cloud_foundry Version < 1.4.1
Newrelic ≫ Dotnet Extension Buildpack SwPlatform pivotal_cloud_foundry Version < 1.1.1
Newrelic ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.12.64
Pagerduty ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.2.4
Riverbed ≫ Steelcentral Appinternals SwPlatform pivotal_cloud_foundry Version < 10.21.1-bl516
Samba ≫ Volume Service SwPlatform pivotal_cloud_foundry Version < 1.1.1
Signalsciences ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.1.0
Snyk ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.0.3
Synopsys ≫ Seeker Iast Service Broker SwPlatform pivotal_cloud_foundry Version < 1.2.14
Tibco ≫ Businessworks Buildpack SwEdition container SwPlatform pivotal_cloud_foundry Version < 2.4.4
Wavefront ≫ Wavefront By Vmware Nozzle SwPlatform pivotal_cloud_foundry Version < 1.0.2
Yugabyte ≫ Db Enterprise SwPlatform pivotal_cloud_foundry Version < 1.1.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 2.09% | 0.792 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 2.1 | 3.9 | 2.9 |
AV:L/AC:L/Au:N/C:P/I:N/A:N
|
| EMC | 6.3 | 2 | 3.7 |
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
|
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.
CWE-522 Insufficiently Protected Credentials
The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.
https://pivotal.io/security/cve-2019-3800
https://www.cloudfoundry.org/blog/cve-2019-3800