7.8

CVE-2019-3800

CF CLI writes the client id and secret to config file

CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Pivotal ≫ Cloud Foundry Deployment Version < 10.0.0
Pivotal ≫ Cloud Foundry Routing Release Version < 0.189.0
Pivotal ≫ Cloud Foundry Smoke Test Version < 40.0.113
Pivotal ≫ Application Service Version >= 2.3.0 < 2.3.14
Pivotal ≫ Application Service Version >= 2.4.0 < 2.4.10
Pivotal ≫ Application Service Version >= 2.5.0 < 2.5.6
Pivotal ≫ Cloud Foundry Event Alerts Version < 1.2.8
Pivotal ≫ Cloud Foundry Healthwatch Version >= 1.4.0 < 1.4.7
Pivotal ≫ Cloud Foundry Healthwatch Version >= 1.5.0 < 1.5.4
Pivotal ≫ On Demand Service Broker Version < 0.29.0
Pivotal ≫ Pivotal Cloud Foundry Service Broker SwPlatform aws Version < 1.4.13
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.7.0 < 1.7.5
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.8.0 < 1.8.4
Pivotal ≫ Single Sign-on SwPlatform cloud_foundry Version >= 1.9.0 < 1.9.1
Anynines ≫ Elasticsearch SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Logme SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Mongodb SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Mysql SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Postgresql SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Rabbitmq SwPlatform pivotal_cloud_foundry Version < 2.1.2
Anynines ≫ Redis SwPlatform pivotal_cloud_foundry Version < 2.1.2
Apigee ≫ Edge Service Broker SwPlatform pivotal_cloud_foundry Version < 3.1.3
Appdynamics ≫ Application Analytics SwPlatform pivotal_cloud_foundry Version < 4.7.652
Appdynamics ≫ Application Performance Monitoring SwPlatform pivotal_cloud_foundry Version < 4.6.64
Appdynamics ≫ Platform Montioring SwPlatform pivotal_cloud_foundry Version < 4.7.712
Bluemedora ≫ Nozzle SwPlatform pivotal_cloud_foundry Version < 3.1.1
Contrastsecurity ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 2.2.0
Cyberark ≫ Conjur Service Broker SwPlatform pivotal_cloud_foundry Version < 1.1.1
Datadoghq ≫ Application Monitoring SwPlatform pivotal_cloud_foundry Version < 1.7.0
Datastax ≫ Enterprise Service Broker SwPlatform pivotal_cloud_foundry Version < 1.0.2
Dynatrace ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.4.2
Forgerock ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 2.1.2
Google ≫ Google Cloud Platform Service Broker SwPlatform pivotal_cloud_foundry Version < 4.2.3
Ibm ≫ Websphere Liberty SwPlatform pivotal_cloud_foundry Version < 3.11.0
Microsoft ≫ Azure Log Analytics Nozzle SwPlatform pivotal_cloud_foundry Version < 1.4.1
Microsoft ≫ Azure Service Broker SwPlatform pivotal_cloud_foundry Version < 1.4.1
Newrelic ≫ Dotnet Extension Buildpack SwPlatform pivotal_cloud_foundry Version < 1.1.1
Newrelic ≫ Nozzle SwPlatform pivotal_cloud_foundry Version < 1.1.17
Newrelic ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.12.64
Pagerduty ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.2.4
Riverbed ≫ Steelcentral Appinternals SwPlatform pivotal_cloud_foundry Version < 10.21.1-bl516
Samba ≫ Volume Service SwPlatform pivotal_cloud_foundry Version < 1.1.1
Signalsciences ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.1.0
Snyk ≫ Service Broker SwPlatform pivotal_cloud_foundry Version < 1.0.3
Solace ≫ Pubsub+ SwPlatform pivotal_cloud_foundry Version < 2.3.2
Splunk ≫ Nozzle SwPlatform pivotal_cloud_foundry Version < 1.1.1
Sumologic ≫ Nozzle SwPlatform pivotal_cloud_foundry Version < 1.0.1
Synopsys ≫ Seeker Iast Service Broker SwPlatform pivotal_cloud_foundry Version < 1.2.14
Tibco ≫ Businessworks Buildpack SwEdition container SwPlatform pivotal_cloud_foundry Version < 2.4.4
Wavefront ≫ Wavefront By Vmware Nozzle SwPlatform pivotal_cloud_foundry Version < 1.0.2
Yugabyte ≫ Db Enterprise SwPlatform pivotal_cloud_foundry Version < 1.1.8
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.09% 0.792
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 2.1 3.9 2.9
AV:L/AC:L/Au:N/C:P/I:N/A:N
EMC 6.3 2 3.7
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

CWE-522 Insufficiently Protected Credentials

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

https://pivotal.io/security/cve-2019-3800
Vendor Advisory
https://www.cloudfoundry.org/blog/cve-2019-3800
Vendor Advisory